Daojing He

dblp:60/7270 · DBLP profile ↗
← Back
124ranked-venue papers
39as first author
88since 2021 · last 2026
0000-0002-3820-8128ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 55 · 25 first-author · 40 since 2021Security and privacy · 26 · 6 first-author · 19 since 2021Artificial intelligence and machine learning · 23 · 23 since 2021Systems, architecture and hardware · 8 · 3 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 8 · 5 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 3 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Malicious Domain Detection on Out-of-Distribution Gray Data through Graph Contrastive Learning with Structure Aggregation
abstract
Graph-based threat detection methods model Indicators of Compromise (IoC) using heterogeneous graphs and train node classifiers to identify malicious domains. Despite their promising performance, these approaches still face two major challenges. Firstly, the high cost of node annotation leads to a lack of evaluation on extensive gray data (unlabeled data). Secondly, the previous observations reveal a significant distribution shift in the Domain Maliciousness Graph (DMG), where structural differences between labeled and unlabeled domains hinder model performance. Existing graph learning methods have not yet considered both of these challenges simultaneously. To fill the gap, we frame the problem as semi-supervised graph node classification under out-of-distribution (OOD) constraints. We introduce graph aggregative contrastive learning (GRAVEL), which leverages the inherent structure of DMG to enhance detection performance on OOD unlabeled domains. GRAVEL is pre-trained end-to-end on abundant in-distribution malicious and benign samples, then fine-tuned with scarce OOD malicious data via mixup. During pre-training, label propagation seeds pseudo-labels, and a label-guided aggregation classifier is used to warm up the model, after which multi-view contrastive learning sharpens features for unlabeled domains. Extensive industrial evaluations demonstrate that GRAVEL improves F1 by 5–20% across diverse benchmarks for OOD malicious domain detection, consistently outperforming state-of-the-art baselines.
Hongjie Gu, Daojing He, Xun Zhou 0001
KDD (1)2
2026 Toward efficient testing of graph neural networks via test input prioritization
Lichen Yang, Qiang Wang 0001, Zhonghao Yang 0003, Daojing He, Yu Li 0007
Autom. Softw. Eng.4
2026 CMSM: Cross-modal semantic matching for lightweight IDS in the IoV
Zhendong Wang 0002, Xiping Zhou, Huamao Xie, Dahai Li, Daojing He, Sammy Chan
Comput. Networks5
2026 Federated learning based on two-stage knowledge distillation for intrusion detection in industrial IoT
Renqiang Zhou, Zhendong Wang 0002, Shuxin Yang, Daojing He, Sammy Chan
Expert Syst. Appl.4
2026 Semantics-Preserving Contrastive Representation Learning for Encrypted Traffic Classification
Shihao Peng, Jinchuan Liu, Daojing He
IEEE Internet Things J.5
2026 A Blockchain-Aided Flexibility Procurement Bargaining for TSO-DSO Coordination
Yongrong Shi, Qisheng Huang, Daojing He, Yunshu Liu, Junping Ji
IEEE Internet Things J.3
2026 ACRM: An Adaptive Cluster Radius Multihop Routing Protocol With Direction Awareness for Large-Scale WSNs
abstract
As the scale of wireless sensor networks (WSNs) continues to expand, challenges such as excessive network energy consumption and load imbalance have become increasingly severe. Existing non-uniform clustering protocols rely on fixed parameters and local information, lack the ability to dynamically perceive global energy differences, and are thus difficult to adapt to the dynamic changes of large-scale networks for balancing energy consumption and load. To address this issue, this paper proposes an adaptive cluster radius multi-hop routing protocol (ACRM) suitable for large-scale WSNs. The protocol provides a decision-making basis for the adjustment of nodes’ personalized competition radii and auction-based cluster head selection through an energy disparity factor quantified based on the Gini coefficient. On this basis, cluster head selection is modeled as a static game with incomplete information. Through an auction mechanism, cluster head seats are allocated according to the principle of maximizing bid prices, and a price decay strategy is introduced to prevent overloading of low-energy nodes. In the routing phase, intra-cluster routing employs hierarchical decision-making to select a subset of nodes for multi-hop communication to reduce energy consumption; while inter-cluster routing establishes multi-hop paths based on a direction-aware scoring mechanism that integrates node direction and energy, effectively avoiding path detours and reverse transmissions. Additionally, unlike existing non-uniform clustering protocols, ACRM effectively addresses the issues of cluster head overload near the base station and excessive energy consumption from frequent clustering through directly connected node offloading and adaptive periodic reconfiguration. Simulation results show that in a 500m×500m network scenario, the network stability period of ACRM reaches 636 rounds, which is over 100% higher than that of protocols such as LEACH, LEACH-OR, EEUC, and DEBUC, approximately 61.8% higher than PUAG, and 18.4% higher than UCRTD; significant improvements are also observed in the overall network lifetime and the number of data packets received by the base station.
Zhendong Wang 0002, Silong Cao, Shuxin Yang, Daojing He, Sammy Chan
IEEE Internet Things J.4
2026 PFedRobust: A personalized federated learning framework toward robustness against data poisoning attacks in IoT
Tao Li 0043, Andrea Bracciali, Daojing He, Zhiquan Liu 0001
Knowl. Based Syst.6
2026 HGAFA: Heterogeneous Graph Attention-Based Featureless Aggregation for IoC Joint Identification
abstract
Malicious cyber activities can potentially be detected through indicators of compromise (IoCs). As attacks become more complex, IoCs can be increasingly interconnected; thus, motivating the use of graph-based modeling. However, current approaches face three key challenges: limited and small-scale benchmarks that hinder industrial applicability, reliance on expert-designed meta-paths that restricts generalization in heterogeneous graphs, and insufficient interpretability, which increases the cost of verifying false positives. To address these challenges, we propose a web-scale IoC heterogeneous graph (IoCHG) that models domains, files, IPs, and URLs with seven interaction types, constructed through malware sandbox execution and open-source threat intelligence. Building on IoCHG, we develop Heterogeneous Graph Attention-based Featureless Aggregation (HGAFA) to support joint IoC identification. HGAFA leverages node and edge attention to capture IoC subgraph structures without meta-paths or hand-crafted features, thereby reducing reliance on expert knowledge. Our approach further improves interpretability through edge masking. To our knowledge, this is the first approach to model large-scale IoCs and identify malicious IoCs without expert-designed features. Experiments on millions of nodes from an industrial dataset show that HGAFA outperforms five competing approaches by an average of 8% in precision, while its interpretable subgraphs assist security experts in analyzing attack scenarios.
Hongjie Gu, Daojing He, Jialun Cao, Gaolei Li, Kim-Kwang Raymond Choo
IEEE Trans. Dependable Secur. Comput.2
2026 PPTD: A Path Profiling-Based Threat Detection Method Toward Deployed Smart Contracts
abstract
Smart contracts have been the target of attackers (e.g., identifying and exploiting vulnerabilities). Existing countermeasures for detecting threats in smart contracts include symbolic execution, formal verification, and fuzzing, most of which only target specific known threats. However, such approaches may not be effective in detecting unknown/unseen threats (e.g., those without predefined vulnerability patterns). Building on the principles of smart contract threats and the immutability property, we propose a path profiling-based threat detection (PPTD) approach. To achieve accurate tracking of cyclic and acyclic paths, PPTD combines the profiling all paths (PAP) algorithm with the efficient path profiling (EPP) algorithm to record contract execution paths. This incurs lower gas overhead while effectively detecting and preventing threats. PPTD obtains legal paths and achieves data flow level detection through fuzzer, and automatically protects vulnerable smart contracts from threats, avoiding manual modification of vulnerable codes. Specifically, our approach is also designed to detect threats and prevent attacks after the contract is deployed, as demonstrated in our evaluations.
Daojing He, Sammy Chan, Kim-Kwang Raymond Choo
IEEE Trans. Dependable Secur. Comput.1
2026 Exploiting Semantics of Special Characters to Strengthen Passwords
Daojing He, Zhiyong Liu 0003, Sammy Chan, Kim-Kwang Raymond Choo
IEEE Trans. Dependable Secur. Comput.1
2026 The Impact of Digit Semantic Patterns on Password Security
abstract
Continuously preventing weak password attacks is one of the most important initiatives to secure IoT systems. Password strength meters can guide users to create secure passwords, but in our investigation, we found that current password strength meters in mainstream IoT systems overestimate the strength of passwords with digit segments, leading users to choose passwords they thought were secure but are actually not. Therefore, we conduct a more in-depth and comprehensive study on the semantic characteristics of digit segments in passwords than ever before. We obtained unpublished high-frequency digit semantic patterns through semantic extraction methods and improved the PCFG attack by utilizing these newly discovered semantic pattern characteristics. The experimental results show that the semantic characteristics of digit segments have an important impact on the strength of user passwords. Finally, we propose a feasible scheme to improve the password strength meter for IoT systems based on the high-frequency semantic characteristics of digit segments.
Daojing He, Zhiyong Liu 0003, Beibei Zhou, Sammy Chan, Kim-Kwang Raymond Choo
IEEE Trans. Dependable Secur. Comput.1
2026 NiIas: Non-Interactive Instant Authentication and Secure Data Delivery Protocol for Multi-Access Edge Computing
abstract
The inherent heterogeneity and mobility of Multi access Edge Computing (MEC) necessitate security protocols that ensure instant connectivity while maintaining resilience against resource exhaustion. This paper presents NiIas, a non-interactive instant authentication and secure data delivery proto col. Unlike conventional protocols that require prior handshakes, NiIas enables immediate payload transmission without session resumption delays. The protocol leverages a multi-authorization identity-based cryptosystem to decentralize trust and eliminate certificate management overhead. Furthermore, NiIas employs an authenticate-before-decryption mechanism as a lightweight admission control. This design filters unauthorized traffic prior to decryption and effectively protects edge verifiers from denial of-service attacks. Rigorous security analysis formally establishes the protocol's cryptographic guarantees. Moreover, numerical simulations on resource-constrained devices and M/D/1 queuing theoretic analysis demonstrate that NiIas achieves superior availability and stability compared to state-of-the-art protocols.
Xuru Li, Daojing He, Lifei Wei, Sammy Chan, Kim-Kwang Raymond Choo, Dezhi Han
IEEE Trans. Dependable Secur. Comput.2
2026 VLM-Guard: Defending Jailbreaks by Monitoring Only Hundreds of Safety-Critical Neurons
Jinyin Hu, Jiawei Zhou 0013, Minshan Xie, Zhonghao Yang 0003, Jing Li 0034, Huadi Zheng, Jie Shi 0005, Daojing He, Yu Li 0007
IEEE Trans. Inf. Forensics Secur.8
2025 DF-MIA: A Distribution-Free Membership Inference Attack on Fine-Tuned Large Language Models
abstract
Membership Inference Attack (MIA) aims to determine if a specific sample is present in the training dataset of a target machine learning model. Previous MIAs against fine-tuned Large Language Models (LLMs) either fail to address the unique challenges in the fine-tuned setting or rely on strong assumption of the training data distribution. This paper proposes a distribution-free MIA framework tailored for fine-tuned LLMs, named DF-MIA. We recognize that samples await to test can serve as a valuable reference dataset for fine-tuning reference models. By enhancing the signals of non-member samples within this reference dataset, we can achieve a more reliable and practical calibration of probabilities, improving the differentiation between members and non-members. Leveraging these insights, we have developed a two-stage framework that employs specially designed data augmentation and perturbation techniques to prioritize the significance of non-members and mitigate the influence of potential members within the reference dataset. We evaluate our method on three representative LLM models ranging from 1B to 8B on three datasets. The results demonstrate that the DF-MIA significantly enhances the performance of MIA.
Zhiheng Huang, Yannan Liu, Daojing He, Yu Li 0007
AAAI3
2025 Knowledge Editing with Dynamic Knowledge Graphs for Multi-Hop Question Answering
abstract
Multi-hop question answering (MHQA) poses a significant challenge for large language models (LLMs) due to the extensive knowledge demands involved. Knowledge editing, which aims to precisely modify the LLMs to incorporate specific knowledge without negatively impacting other unrelated knowledge, offers a potential solution for addressing MHQA challenges with LLMs. However, current solutions struggle to effectively resolve issues of knowledge conflicts. Most parameter-preserving editing methods are hindered by inaccurate retrieval and overlook secondary editing issues, which can introduce noise into the reasoning process of LLMs. In this paper, we introduce KEDKG, a novel knowledge editing method that leverages a dynamic knowledge graph for MHQA, designed to ensure the reliability of answers. KEDKG involves two primary steps: dynamic knowledge graph construction and knowledge graph augmented generation. Initially, KEDKG autonomously constructs a dynamic knowledge graph to store revised information while resolving potential knowledge conflicts. Subsequently, it employs a fine-grained retrieval strategy coupled with an entity and relation detector to enhance the accuracy of graph retrieval for LLM generation. Experimental results on benchmarks show that KEDKG surpasses previous state-of-the-art models, delivering more accurate and reliable answers in environments with dynamic information.
Yigeng Zhou, Jing Li 0034, Yequan Wang, Xuebo Liu 0002, Daojing He, Fangming Liu, Min Zhang 0005
AAAI6
2025 Neural Parameter Search for Slimmer Fine-Tuned Models and Better Transfer
abstract
Guodong Du, Zitao Fang, Jing Li, Junlin Li, Runhua Jiang, Shuyang Yu, Yifei Guo, Yangneng Chen, Sim Kuan Goh, Ho-Kin Tang, Daojing He, Honghai Liu, Min Zhang. Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2025.
Guodong Du 0002, Zitao Fang, Jing Li 0034, Runhua Jiang, Shuyang Yu, Yifei Guo, Yangneng Chen, Sim Kuan Goh, Ho-Kin Tang, Daojing He, Honghai Liu 0001, Min Zhang 0005
ACL (1)11
2025 MTSA: Multi-turn Safety Alignment for LLMs through Multi-round Red-teaming
abstract
The proliferation of jailbreak attacks against large language models (LLMs) highlights the need for robust security measures.However, in multi-round dialogues, malicious intentions may be hidden in interactions, leading LLMs to be more prone to produce harmful responses.In this paper, we propose the Multi-Turn Safety Alignment (MTSA) framework, to address the challenge of securing LLMs in multi-round interactions.It consists of two stages: In the thought-guided attack learning stage, the redteam model learns about thought-guided multiround jailbreak attacks to generate adversarial prompts.In the adversarial iterative optimization stage, the red-team model and the target model continuously improve their respective capabilities in interaction.Furthermore, we introduce a multi-turn reinforcement learning algorithm based on future rewards to enhance the robustness of safety alignment.Experimental results show that the red-team model exhibits state-of-the-art attack capabilities, while the target model significantly improves its performance on safety benchmarks.
Weiyang Guo, Jing Li 0034, Wenya Wang 0001, Yu Li 0007, Daojing He, Jun Yu 0002, Min Zhang 0005
ACL (1)5
2025 Multi-Modality Expansion and Retention for LLMs through Parameter Merging and Decoupling
abstract
Junlin Li, Guodong Du, Jing Li, Sim Kuan Goh, Wenya Wang, Yequan Wang, Fangming Liu, Ho-Kin Tang, Saleh Alharbi, Daojing He, Min Zhang. Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2025.
Guodong Du 0002, Jing Li 0034, Sim Kuan Goh, Wenya Wang 0001, Yequan Wang, Fangming Liu, Ho-Kin Tang, Saleh Alharbi, Daojing He, Min Zhang 0005
ACL (1)10
2025 Safety Alignment via Constrained Knowledge Unlearning
abstract
Zesheng Shi, Yucheng Zhou, Jing Li, Yuxin Jin, Yu Li, Daojing He, Fangming Liu, Saleh Alharbi, Jun Yu, Min Zhang. Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2025.
Zesheng Shi, Yucheng Zhou 0001, Jing Li 0034, Yu Li 0007, Daojing He, Fangming Liu, Saleh Alharbi, Jun Yu 0002, Min Zhang 0005
ACL (1)6
2025 Enhancing Spatial Reasoning in Multimodal Large Language Models Through Reasoning-Based Segmentation
abstract
Recent advances in point cloud perception have demonstrated remarkable progress in scene understanding through vision-language alignment leveraging large language models (LLMs). However, existing methods may still encounter challenges in handling complex instructions that require accurate spatial reasoning, even if the 3D point cloud data provides detailed spatial cues such as size and position for identifying the targets. To tackle this issue, we propose Relevant Reasoning Segmentation (R$^2$S), a reasoning-based segmentation framework. The framework emulates human cognitive processes by decomposing spatial reasoning into two sequential stages: first identifying relevant elements, then processing instructions guided by their associated visual priors. Furthermore, acknowledging the inadequacy of existing datasets in complex reasoning tasks, we introduce 3D ReasonSeg, a reasoning-based segmentation dataset comprising 25,185 training samples and 3,966 validation samples with precise annotations. Both quantitative and qualitative experiments demonstrate that the R$^2$S and 3D ReasonSeg effectively endow 3D point cloud perception with stronger spatial reasoning capabilities, and we hope that they can serve as a new baseline and benchmark for future work.
Zhenhua Ning, Zhuotao Tian, Shaoshuai Shi, Guangming Lu 0002, Daojing He, Wenjie Pei, Li Jiang 0009
ICCV5
2025 One Model Transfer to All: On Robust Jailbreak Prompts Generation against LLMs
abstract
Safety alignment in large language models (LLMs) is increasingly compromised by jailbreak attacks, which can manipulate these models to generate harmful or unintended content. Investigating these attacks is crucial for uncovering model vulnerabilities. However, many existing jailbreak strategies fail to keep pace with the rapid development of defense mechanisms, such as defensive suffixes, rendering them ineffective against defended models. To tackle this issue, we introduce a novel attack method called ArrAttack, specifically designed to target defended LLMs. ArrAttack automatically generates robust jailbreak prompts capable of bypassing various defense measures. This capability is supported by a universal robustness judgment model that, once trained, can perform robustness evaluation for any target model with a wide variety of defenses. By leveraging this model, we can rapidly develop a robust jailbreak prompt generator that efficiently converts malicious input prompts into effective attacks. Extensive evaluations reveal that ArrAttack significantly outperforms existing attack strategies, demonstrating strong transferability across both white-box and black-box models, including GPT-4 and Claude-3. Our work bridges the gap between jailbreak attacks and defenses, providing a fresh perspective on generating robust jailbreak prompts.
Linbao Li, Yannan Liu, Daojing He, Yu Li 0007
ICLR3
2025 Context-Aware Hierarchical Learning: A Two-Step Paradigm towards Safer LLMs
abstract
Large Language Models (LLMs) have emerged as powerful tools for diverse applications. However, their uniform token processing paradigm introduces critical vulnerabilities in instruction handling, particularly when exposed to adversarial scenarios. In this work, we identify and propose a novel class of vulnerabilities, termed Tool-Completion Attack (TCA), which exploits function-calling mechanisms to subvert model behavior. To evaluate LLM robustness against such threats, we introduce the Tool-Completion benchmark, a comprehensive security assessment framework, which reveals that even state-of-the-art models remain susceptible to TCA, with surprisingly high attack success rates. To address these vulnerabilities, we introduce Context-Aware Hierarchical Learning (CAHL), a sophisticated mechanism that dynamically equilibrates semantic comprehension with role-specific instruction constraints. CAHL leverages the contextual correlations between different instruction segments to establish a robust, context-aware instruction hierarchy. Extensive experiments demonstrate that CAHL significantly enhances LLM robustness against both conventional attacks and the proposed TCA, exhibiting strong generalization capabilities in zero-shot evaluations while still preserving model performance on generic tasks. Our code is available at https://github.com/S2AILab/CAHL.
Tengyun Ma, Daojing He, Shihao Peng, Yu Li 0007, Shaohui Liu, Zhuotao Tian
NeurIPS3
2025 Energy efficient clustering and routing for wireless sensor networks by applying a spider wasp optimizer
Zhendong Wang 0002, Yaozhong Yang, Daojing He, Sammy Chan
Ad Hoc Networks4
2025 DTKD-IDS: A dual-teacher knowledge distillation intrusion detection model for the industrial internet of things
Biao Xie, Zhendong Wang 0002, Daojing He, Sammy Chan
Ad Hoc Networks4
2025 ICMH-CHR: An intra-cluster multi-hop based cluster head rotation protocol for wireless sensor networks
Weibing Zeng, Zhendong Wang 0002, Shuxin Yang, Daojing He, Sammy Chan
Ad Hoc Networks4
2025 Blockchain-based efficient and secure cloud cross-domain data sharing with dynamic revocation by multiple authorities
Guangfu Wu, Daojing He, Sammy Chan
Comput. Networks3
2025 Multi-population dynamic grey wolf optimizer based on dimension learning and Laplace Mutation for global optimization
Zhendong Wang 0002, Lei Shu 0001, Shuxin Yang, Daojing He, Sammy Chan
Expert Syst. Appl.5
2025 A Vulnerability Detection Method for Smart Contracts Based on Dynamic Meta Optimizer
abstract
With the increasingly complex blockchain technology environment and emerging security threats, the detection and prevention of vulnerabilities in blockchain smart contracts have become crucial for ensuring the healthy development of blockchain technology and avoiding substantial economic losses. Recently developed vulnerability detection methods for smart contracts suffer from the drawbacks of insufficient feature extraction and inadequate multitask detection. This paper proposes a multifaceted learning model, DLR, based on a dual-loop architecture of meta learning to address these issues by adopting model-agnostic meta-learning techniques. This model employs a syntax analyzer for targeted feature extraction, with graph information used as a supporting tool during the initial stage of feature engineering. Combined with an improved optimizer algorithm in the inner loop, the model can effectively learn and adjust based on the specific requirements of each task. In the outer loop, the model achieves efficient learning rate adjustment for multi-task learning by integrating the adaptive learning rate of the Adam optimizer with a global adjustment using simulated annealing strategy, thereby enhancing performance across diverse tasks. Experimental results demonstrate significant improvements in detection accuracy over state-of-the-art methods for three types of vulnerabilities, with our method achieving detection accuracies of 94.40%, 93.36%, and 94.33% for reentrancy, timestamp dependence, and integer overflow vulnerabilities, respectively.
Daojing He, Sammy Chan
IEEE Internet Things J.1
2025 HASHL: Dynamic Hash Verification for Detecting and Preventing Eclipse Attacks
abstract
With the rapid development of blockchain technology, P2P networks are facing increasing security threats, among which Eclipse attacks, as a type of network isolation attack, have seriously affected the normal operation of the network and the integrity of data. To address this challenge, this study implements node authentication and dynamic reputation evaluation by leveraging a dynamic hash computation mechanism that integrates challenge strings, node identifiers, and the latest active time, ensuring the uniqueness of node identities and the authenticity of operations. Based on a dynamic hash chain behavior evaluation mechanism, node behaviors are quantified across three dimensions: integrity, consistency, and temporal consistency, enabling precise identification of anomalous nodes. Furthermore, a network prevention repository framework is proposed, which dynamically adjusts the trust index of nodes by combining historical behavior with real-time data, effectively detecting and defending against stealthy Eclipse attacks. In addition, extensive testing on both Bitcoin and Ethereum platforms has shown that the method proposed in this study not only can effectively coexist on these two platforms, but also significantly improves the security and stability of the network, effectively reducing the occurrence of Eclipse attacks.
Daojing He, Chen Tu, Sammy Chan
IEEE Internet Things J.1
2025 A Secure and Efficient Software Random Number Generator Applicable to Internet of Things
abstract
The application of random numbers is essential in the Internet of Things (IoT), ranging from traditional data encryption functions to secure and trustworthy technologies for intelligent IoT devices. Due to their unique advantages of flexibility and convenience, software random number generators (SRNGs) are widely used in various computational applications within IoT. The research focus is on the quality, efficiency, and structural security of the output random sequences. However, there is no completely unified structural standard for SRNGs. For instance, even widely used generators, such as the Linux generator have certain deficiencies in the quality or security of their random sequence outputs. This article proposes a more secure and efficient software random number generator, namely SESRNG. First, a dual entropy pool system is constructed using a circular shift register connected to a ring aggregation pool. This system collects multiple system entropy sources in two rounds, with Shannon entropy estimation applied for online entropy estimation of the source data. Next, we utilize dual chaotic systems as extension functions to iteratively compute the entropy source data. In the designed deterministic random number generator structure, the SHA256 algorithm is used as a post-processing function to hash the key parameters of the internal state, resulting in the final random sequence. We used three well-known test suites—ENT, NIST, and the “Information Security Technology Randomness Test Methods for Binary Sequences”—to evaluate the performance of the SRNG. The results show that SESRNG can provide high-quality random numbers that meet the needs of various IoT applications.
Daojing He, Weiwen Huang, Sammy Chan
IEEE Internet Things J.1
2025 RDLSH: Adaptive Entity Recognition and Relation Extraction for IoT Knowledge Graph
abstract
With the rapid development of the Internet of Things (IoT), security issues are becoming increasingly severe. Malicious attackers use IoT devices to carry out network attacks, resulting in data leakage. The use of knowledge graphs effectively prevents and resists attacks through deep mining and association analysis in security situation awareness and threat prediction. Entity recognition and relationship extraction are the core steps in the construction of knowledge graphs. They are used to automatically extract meaningful entities and relationships from massive data and perform reasoning, but they still face challenges in accuracy and computational cost in extracting long texts and complex relationships. To address these issues, this paper proposes the RDLSH model for processing of local context, low-frequency entity recognition, and global semantic associations. Based on the Reformer architecture, it dynamically adjusts the local sensitive hashing parameters, and combines the multi-head attention mechanism to achieve good performance in capturing cross-paragraph and long-distance dependencies, and efficiently handles entity recognition and relationship extraction tasks. In addition, the RDLSH model introduces reversible residual networks and bidirectional transfer mechanisms to optimize the memory usage of large-scale data processing and improve computational efficiency. Experimental results show that the RDLSH model not only improves the accuracy of entity and relationship extraction, but also enhances the cross-sentence dependency processing capability and computational efficiency.
Daojing He, Chen Tu, Sammy Chan
IEEE Internet Things J.1
2025 A Novel Lightweight IoT Intrusion Detection Model Based on Self-Knowledge Distillation
abstract
The Internet of Things (IoT) environment contains many different types of devices, each with different functionalities, communication protocols, and security capabilities, which makes the IoT a complex challenge for security protection. Therefore, network intrusion detection (NID) is needed to detect intrusions in the network to secure the IoT. In recent years, deep learning (DL)-based intrusion detection systems have achieved excellent results, but they tend to require high-computational resources and storage space, which is not feasible for most IoT devices. In this article, we propose a lightweight intrusion detection model based on self-knowledge distillation (SKD), namely, tied block convolution lightweight deep neural network (TBCLNN), which improves the detection accuracy while also reducing the number of model parameters and computational cost. Specifically, we use the binary Harris Hawk optimization algorithm (bHHO) for dimensionality reduction of traffic features. We use lightweight convolution, such as tied block convolution (TBC), to design lightweight neural network (LNN) models with residual and inverse residual structures. Moreover, we propose an improved SKD loss function to solve the sample imbalance problem and compensate for the performance degradation caused by lightweight neural networks. The multiclassification accuracy of our proposed method exceeds 99% on all three publicly available IoT datasets. The experimental results show that our method has a small model size and requires only low-computational resources, making it suitable for resource-constrained IoT intrusion detection.
Zhendong Wang 0002, Renqiang Zhou, Shuxin Yang, Daojing He, Sammy Chan
IEEE Internet Things J.4
2025 Self-Simulation and Meta-Model Aggregation-Based Heterogeneous-Graph-Coupled Federated Learning
abstract
A heterogeneous information network (heterogeneous graph) federated learning plays a crucial role in enabling multiparty collaboration in the Internet of Things system. However, due to differences in business and data, the local models of each participant are heterogeneous and unable to achieve federated aggregation. Furthermore, the nonindependent and identically distributed (non-IID) coupling topology structure among participants severely impacts the performance of federated learning. Given the lack of appropriate solutions to these issues, this study proposes a novel heterogeneous graph federated learning framework (HGFL+) based on self-simulation and meta-model aggregation, which includes the following two innovative techniques: 1) the missing coupling supplement module simulates new neighbor nodes on its original heterogeneous graph, and constructs associated edges using multiple encoder-decoder structures, thereby achieving the supplement of missing neighbors with better results than external generative methods and 2) the heterogeneous model aggregation algorithm realizes the fusion of multiparty heterogeneous graph information through mapping, splitting, aggregating, and recombining multiple stages based on the meta-model (the largest basic model unit among participants). We theoretically analyzed the applicability and effectiveness of HGFL+, demonstrating the generalization boundary of HGFL+. Meanwhile, multidimensional empirical verification of classification performance, convergence effect, time overhead, model size, and application extension (model, task, domain) validates the effectiveness of the proposed method.
Caihong Yan, Pietro Liò, Pan Hui 0001, Daojing He
IEEE Internet Things J.5
2025 Enhancing Android malware detection via knowledge distillation on homogenized function call graphs
Zhendong Wang 0002, Shuxin Yang, Daojing He, Sammy Chan
Knowl. Based Syst.4
2025 Lightweight model-contrastive federated learning with multi-center clustering for IoT intrusion detection
Renqiang Zhou, Zhendong Wang 0002, Shuxin Yang, Daojing He, Sammy Chan
Knowl. Based Syst.4
2025 Toward Robust and Accurate Adversarial Camouflage Generation Against Vehicle Detectors
abstract
Adversarial camouflage is a widely used physical attack against vehicle detectors for its superiority in multiview attack performance. One promising approach involves using differentiable neural renderers to facilitate adversarial camouflage optimization through gradient back-propagation. However, existing methods often struggle to capture environmental characteristics during the rendering process or produce adversarial textures that can precisely map to the target vehicle. Moreover, these approaches neglect diverse weather conditions, reducing the efficacy of generated camouflage across varying weather scenarios. To tackle these challenges, we propose a robust and accurate camouflage generation method, namely RAUCA. The core of RAUCA is a novel neural rendering component, End-to-End Neural Renderer Plus (E2E-NRP), which can accurately optimize and project vehicle textures and render images with environmental characteristics such as lighting and weather. In addition, we integrate a multi-weather dataset for camouflage generation, leveraging the E2E-NRP to enhance the attack robustness. Experimental results on six popular object detectors show that RAUCA-final outperforms existing methods in both simulation and real-world settings.
Jiawei Zhou 0013, Linye Lyu, Daojing He, Yu Li 0007
IEEE Trans. Dependable Secur. Comput.3
2025 ArcGen: Generalizing Neural Backdoor Detection Across Diverse Architectures
abstract
Backdoor attacks pose a significant threat to the security and reliability of deep learning models. To mitigate such attacks, one promising approach is to learn to extract features from the target model and use these features for backdoor detection. However, we discover that existing learning-based neural backdoor detection methods do not generalize well to new architectures not seen during the learning phase. In this paper, we analyze the root cause of this issue and propose a novel black-box neural backdoor detection method called ARCGEN. Our method aims to obtain architecture-invariant model features, i.e.,aligned features, for effective backdoor detection. Specifically, in contrast to existing methods directly using model outputs as model features, we introduce an additional alignment layer in the feature extraction function to further process these features. This reduces the direct influence of architecture information on the features. Then, we design two alignment losses to train the feature extraction function. These losses explicitly require that features from models with similar backdoor behaviors but different architectures are aligned at both the distribution and sample levels. With these techniques, our method demonstrates up to 42.5% improvements in detection performance (e.g., AUC) on unseen model architectures. This is based on a large-scale evaluation involving 16,896 models trained on diverse datasets, subjected to various backdoor attacks, and utilizing different model architectures. Our code is available at https://github.com/SeRAlab/ArcGen.
Zhonghao Yang 0003, Daojing He, Yiming Li 0004, Yu Li 0007
IEEE Trans. Inf. Forensics Secur.3
2025 Blockchain Assisted Trust Management for Data-Parallel Distributed Learning
abstract
Machine learning models can support decision-making in mobile terminals (MTs) deployments, but their training generally requires massive datasets and abundant computation resources. This is challenging in practice due to the resource constraints of many MTs. To address this issue, data-parallel distributed learning can be conducted by offloading computation tasks from MTs to the edge-layer nodes. To facilitate the establishment of trust, one can leverage trust management, say to use trust values derived from local model quality and evaluations by other nodes as access criteria. Nonetheless, security and performance considerations remain unsolved. In this paper, we propose a blockchain-assisted dynamic trust management scheme for distributed learning, which comprises nodes attributes registration, trust calculation, information saving, and block writing. The proof of stake (PoS) consensus mechanism is leveraged to enable efficient consensus among the nodes using trust values as stakes. The incentive mechanism and corresponding dynamic optimization are then proposed to further improve system performance and security. The reinforcement-learning approach is leveraged to provide the optimal strategy for nodes’ local iterations and selection. Simulations and security analysis demonstrate that our proposed scheme can achieve an optimal trade-off between efficiency and quality of distributed learning while maintaining system security.
Yuxiao Song, Daojing He, Minghui Dai, Sammy Chan, Kim-Kwang Raymond Choo, Mohsen Guizani
IEEE Trans. Mob. Comput.2
2025 Cost-Efficient and Privacy-Preserving Distributed Learning: A Double Layer-Based Auction Design
abstract
The rise of artificial intelligence of things (AIoT) has enabled AI-powered services within wireless networks, relying on well-trained machine learning (ML) models. Distributed learning, such as federated learning (FL), allows smart devices (SDs) to collaborate on model training without sharing raw data, but privacy protection is still necessary to prevent potential information leakage from evolving attacks. Additionally, training efficiency is hampered by limited resources and selfishness of SDs. This paper considers a layered distributed learning scenario using a double-layer auction approach, where model users act as buyers, SDs act as data owners contributing their datasets, and edge layer nodes (ELNs) serve as model trainers providing computing resources. The differential privacy (DP) mechanism is utilized to add Gaussian noise to the trained models by the ELNs. Then, we formulate a joint optimization problem to optimize task assignment, data owners' sensing durations, and model trainers' local iterations and privacy budgets, aiming to maximize the utility of all participants while ensuring cost-effective and privacy-preserving distributed learning. We decompose the formulated problem into four sub-problems and design a layered algorithm to solve them and derive collaboration strategies. Simulation results validate the algorithm's performance and demonstrate the advantages of our proposed approach compared to benchmark schemes.
Yuxiao Song, Daojing He, Minghui Dai, Mohsen Guizani
IEEE Trans. Mob. Comput.2
2024 RAUCA: A Novel Physical Adversarial Attack on Vehicle Detectors via Robust and Accurate Camouflage Generation
abstract
Adversarial camouflage is a widely used physical attack against vehicle detectors for its superiority in multi-view attack performance. One promising approach involves using differentiable neural renderers to facilitate adversarial camouflage optimization through gradient back-propagation. However, existing methods often struggle to capture environmental characteristics during the rendering process or produce adversarial textures that can precisely map to the target vehicle, resulting in suboptimal attack performance. Moreover, these approaches neglect diverse weather conditions, reducing the efficacy of generated camouflage across varying weather scenarios. To tackle these challenges, we propose a robust and accurate camouflage generation method, namely RAUCA. The core of RAUCA is a novel neural rendering component, Neural Renderer Plus (NRP), which can accurately project vehicle textures and render images with environmental characteristics such as lighting and weather. In addition, we integrate a multi-weather dataset for camouflage generation, leveraging the NRP to enhance the attack robustness. Experimental results on six popular object detectors show that RAUCA consistently outperforms existing methods in both simulation and real-world settings.
Jiawei Zhou 0013, Linye Lyu, Daojing He, Yu Li 0007
ICML3
2024 Enhancing Flow Embedding Through Trace: A Novel Self-supervised Approach for Encrypted Traffic Classification
abstract
Traffic classification is a crucial task in network security and management. Recent research has shown the effectiveness of deep learning when applied to encrypted traffic classification. However, the reliance of deep learning models on abundant labeled and balanced data poses challenges, particularly in traffic analysis where labeling is costly and imbalanced traffic distribution is common. To tackle this challenge, researchers have proposed self-supervised representation learning. This approach aims to derive universal traffic representations from vast amounts of unlabeled data, reducing the need for extensive labeling in downstream tasks. Current representation learning methods predominantly focus on exploring flow-level information, neglecting valuable trace information crucial for effective flow representation learning. In this study, we introduce SAFE, a self-supervised learning methodology tailored for flow representation learning. SAFE specifically delves into trace-level (i.e., a mixture of correlated flows) information to enhance flow embedding. Moreover, our analysis reveals that existing encrypted traffic datasets often contain numerous invalid samples. SAFE conducts a comprehensive examination of dataset characteristics, filtering out these invalid samples, thereby advancing the field significantly. Extensive experiments demonstrate that SAFE outperforms state-of-the-art methods.
Zefei Luo, Yu Li 0007, Shuaishuai Tan, Daojing He
IJCNN4
2024 PPTFI: Patch Presence Test for Function-Irrelevant Patches
abstract
In the past decades, downstream manufacturers often failed to timely adopt the security patches, resulting in some discovered vulnerabilities still posing serious risks. In the currently popular field of blockchain smart contracts, this is also a thorny issue. Although some new methods have been proposed to update and patch smart contracts deployed in blockchain networks, the binary codes of most vulnerable smart contracts are still being executed without patching. To detect the unpatched binaries as soon as possible, signature based patch presence tests and software similarity based patch presence tests have been proposed to check whether a certain patch is applied to the released software binaries. However, a large number of bug-fix patches are irrelevant to functions. They are small in size and only modify program entities other than functions. Existing signature-based patch detection methods and software similarity-based tools have limitations in detecting such patches. In this paper, we propose PPTFI, a patch presence test for function-irrelevant patches. PPTFI understands these patches and extracts code and data information as patch signatures for scanning target binaries. Being evaluated on 62 different versions of 31 real-world function-irrelevant patches and 512 binaries across 16 various compilation environments, PPTFI achieves an accuracy of 77.54%, significantly outperforming existing techniques.
Daojing He, Juzheng Zhang, Sencun Zhu, Sammy Chan
MSN1
2024 Parameter Competition Balancing for Model Merging
abstract
While fine-tuning pretrained models has become common practice, these models often underperform outside their specific domains. Recently developed model merging techniques enable the direct integration of multiple models, each fine-tuned for distinct tasks, into a single model. This strategy promotes multitasking capabilities without requiring retraining on the original datasets. However, existing methods fall short in addressing potential conflicts and complex correlations between tasks, especially in parameter-level adjustments, posing a challenge in effectively balancing parameter competition across various tasks. This paper introduces an innovative technique named **PCB-Merging** (Parameter Competition Balancing), a *lightweight* and *training-free* technique that adjusts the coefficients of each parameter for effective model merging. PCB-Merging employs intra-balancing to gauge parameter significance within individual tasks and inter-balancing to assess parameter similarities across different tasks. Parameters with low importance scores are dropped, and the remaining ones are rescaled to form the final merged model. We assessed our approach in diverse merging scenarios, including cross-task, cross-domain, and cross-training configurations, as well as out-of-domain generalization. The experimental results reveal that our approach achieves substantial performance enhancements across multiple modalities, domains, model sizes, number of tasks, fine-tuning forms, and large language models, outperforming existing model merging methods.
Guodong Du 0002, Junlin Lee, Jing Li 0034, Runhua Jiang, Yifei Guo, Shuyang Yu, Hanting Liu, Sim Kuan Goh, Ho-Kin Tang, Daojing He, Min Zhang 0005
NeurIPS10
2024 CNCA: Toward Customizable and Natural Generation of Adversarial Camouflage for Vehicle Detectors
abstract
Prior works on physical adversarial camouflage against vehicle detectors mainly focus on the effectiveness and robustness of the attack. The current most successful methods optimize 3D vehicle texture at a pixel level. However, this results in conspicuous and attention-grabbing patterns in the generated camouflage, which humans can easily identify. To address this issue, we propose a Customizable and Natural Camouflage Attack (CNCA) method by leveraging an off-the-shelf pre-trained diffusion model. By sampling the optimal texture image from the diffusion model with a user-specific text prompt, our method can generate natural and customizable adversarial camouflage while maintaining high attack performance. With extensive experiments on the digital and physical worlds and user studies, the results demonstrate that our proposed method can generate significantly more natural-looking camouflage than the state-of-the-art baselines while achieving competitive attack performance.
Linye Lyu, Jiawei Zhou 0013, Daojing He, Yu Li 0007
NeurIPS3
2024 Threshold Key Management and Signature in Dynamic Distributed System
Daojing He
SecureComm (2)2
2024 Multi-strategy enhanced grey wolf algorithm for obstacle-aware WSNs coverage optimization
Zhendong Wang 0002, Lili Huang 0001, Shuxin Yang, Daojing He, Sammy Chan
Ad Hoc Networks5
2024 GSASG: Global Sparsification With Adaptive Aggregated Stochastic Gradients for Communication-Efficient Federated Learning
abstract
This article addresses the challenge of communication efficiency in federated learning by the proposed algorithm called global sparsification with adaptive aggregated stochastic gradients (GSASGs). GSASG leverages the advantages of local sparse communication, global sparsification communication, and adaptive aggregated gradients. More specifically, we devise an efficient global top-$k^{\prime }$sparsification operator. By applying this operator to the aggregated gradients obtained from the top-k sparsification, the global model parameter is rarefied to reduce the download transmitted bits from$O(dMT)$to$O(k^{\prime }MT)$, where d is the dimension of the gradient, M is the number of workers, T is the total number of epochs, and$k^{\prime } \leq k\lt d$. Meanwhile, the adaptive aggregated gradient method is adopted to skip meaningless communication and reduce communication rounds. The deep neural network training experiment demonstrates that, compared to the previous algorithms GSASG significantly reduces communication cost without sacrificing the model performance. For instance, when considering the MNIST data set with$k=1\% d$and$k^{\prime }=0.5\% d$, in terms of communication rounds, GSASG outperforms sparse communication by 91%, adaptive aggregated gradients by 90%, and the combination of sparse communication with adaptive aggregated gradients by 56%. In terms of communication bits, GSASG yields 1% of the communication bits needed with previous algorithms.
Runmeng Du, Daojing He, Zikang Ding, Sammy Chan, Xuru Li
IEEE Internet Things J.2
2024 Unknown Threats Detection Methods of Smart Contracts
abstract
With the explosive growth of blockchain platforms and applications, security threats of blockchain also occur frequently. As a decentralized application deployed on the blockchain, smart contracts help the blockchain realize safe and efficient information storage, asset management, and value transfer. Therefore, smart contracts play a vital role in the security of the blockchain. In recent years, security threats against smart contracts have increased, not only causing huge economic losses but also impacting the credit system of the blockchain. Therefore, many researchers have carried out corresponding research on the security threats of smart contracts. Common threat detection methods include formal verification, symbolic execution, fuzzing, etc. Most of these methods are only for known threats, while there is not much work on detecting unknown threats. In order to better deal with unknown threats, we present a review of the typical smart contract security events in recent years, analyze the security threats from contract coding, Ethereum virtual machine, and blockchain characteristics. Further, we compare and summarize the latest unknown threat detection methods. Then, to address the problem that very few unknown threat samples are available, a detection method based on a few-shot learning is proposed.
Daojing He, Sammy Chan, Mohsen Guizani
IEEE Internet Things J.1
2024 A Comprehensive Detection Method for the Lateral Movement Stage of APT Attacks
abstract
Due to the outbreak of the new crown epidemic, more companies prefer to use telecommuting for work, which also provides more attack surfaces for APT attacks. After initially gaining access to the intranet, attackers will use server message block (SMB), RDP, and other remote sharing or connection protocols to move horizontally to achieve the purpose of privilege escalation. In this work, we design a multidimensional detection framework to detect lateral movement behavior based on the SMB protocol in the intranet environment. This framework combines active trapping and passive scanning, and uses neural networks to determine the attack samples used by the adversary when moving laterally. We test the effectiveness of the active trapping technology in a simulation environment, and verify through real malware samples that the accuracy of neural network detection can reach about 90%. The experimental results show that our work can effectively detect the lateral movement behavior using the SMB protocol in the intranet environment.
Daojing He, Hongjie Gu, Sammy Chan, Mohsen Guizani
IEEE Internet Things J.1
2024 On Phishing URL Detection Using Feature Extension
abstract
Phishing is a common cybercrime event with great harm. Various phishing attacks have occurred repeatedly and have caused huge economic losses. With the booming development of blockchain and cryptocurrency, the huge amount of money in the field and the immature ecosystem have induced phishing attacks to flood the field in large quantities. Unfortunately, phishing has become the main means of attack in the field, posing a huge security threat to users’ digital assets. The existing methods for detecting phishing websites rely on the quality of uniform resource locator (URL) feature extraction, and the extraction angle is becoming increasingly rigid. Therefore, this article proposes a phishing URL detection model that utilizes feature extension. This method uses the TextRank algorithm to generate a feature extension library and embeds the extracted features into the URL to be detected. After the URL is vectorized, it is input into the two-layer classification network proposed in this article to classify the website. This classifier consists of an upstream task Bert layer and a downstream task convolutional neural network layer. It is possible to simultaneously learn the comprehensive representation information and local feature information of URLs, effectively avoiding overfitting problems and improving the ability to identify phishing websites. Comparative experiments are conducted using a data set of real phishing websites. The experimental results show that this model has higher accuracy and stability compared to other phishing website detection models.
Daojing He, Sammy Chan, Mohsen Guizani
IEEE Internet Things J.1
2024 A Method for Detecting Phishing Websites Based on Tiny-Bert Stacking
abstract
The Internet is an indispensable part of our lives. Therefore, it is very important to ensure network security and maintain a safe network environment. Phishing, as a low-cost and imperceptible network attack, is rampant in the world’s information networks. To address this issue, this paper proposes a phishing website detection model based on tiny-Bert stacking. The core concept of the proposed model is to use tiny-Bert to extract features from website URL strings, and learn the semantic features and long-range dependent features in URLs. Then we build a Stacking algorithm-based classifier which includes four basic learners among which, CatBoost, XGBoost and LightGBM are the first-level learners, and GBDT is the second-level learner. This detection model can identify phishing websites without manual feature extraction, and the basic learners of Stacking can compensate each other for errors in the classification process, improve generalization, and achieve higher accuracy. The proposed model is evaluated using a dataset based on real phishing websites. Compared to the state of the art, the results show that the proposed model has an accuracy rate of up to 99.14%, a recall rate of up to 99.13%, and is more stable.
Daojing He, Sammy Chan, Kim-Kwang Raymond Choo
IEEE Internet Things J.1
2024 Special Characters Usage and Its Effect on Password Security
abstract
Continuously preventing weak password attacks is one of the most important initiatives to secure IoT and smart contract platforms. Despite their significance as crucial components of passwords, special character segments have been overlooked. This study systematically studies the basic characteristics and semantic patterns of special character segments. We assess the efficacy of special character segment characteristics in cracking trials through assimilation into the latest Probabilistic Context-Free Grammar (PCFGv4) method for password cracking by updating the pre-terminal structure or performing special character segment transformation. Experimental findings demonstrate that a mere 6% transformation rate improves the cracking rate by 3.72% under the optimal assimilation combination. Our investigation reveals that the current password creation policies of mainstream IoT platforms and smart contract wallets overestimate the strength of passwords with special characters. To enhance their passwords, users can employ low-frequency special character semantic strings. For IoT platforms or smart contract wallets, the use of blacklist constructed from special character segment characteristics can effectively mitigate the risk of overestimating the strength of passwords with special characters.
Daojing He, Zhiyong Liu 0003, Sammy Chan, Mohsen Guizani
IEEE Internet Things J.1
2024 Multiround Efficient and Secure Truth Discovery in Mobile Crowdsensing Systems
abstract
Privacy-preserving truth discovery, as a data aggregation algorithm that can extract reliable results from disparate and conflicting data in a privacy-preserving manner, has received a lot of attention in ensuring the reliability and privacy of data in mobile crowdsensing systems. However, most of the existing work requires that workers must stay online all the time during the full process of truth discovery. Although a few recent schemes have been proposed to tolerate worker dropout, they are tailored for a single-round setting. Repeating these schemes several times to adapt to the truth discovery will introduce significant computational and communication overheads, especially for the workers. To solve the above challenges, in this paper, we propose a multi-round efficient and secure truth discovery scheme in mobile crowdsensing systems that can balance the 3-way trade-off between privacy protection, dropout tolerance, and protocol efficiency. Specifically, we devise a novel mask generation capable of reusing secrets to eliminate the costly overhead of workers needing to recompute new secrets each round. Besides, we design a lightweight dropout tolerance mechanism to guarantee that even if workers drop out halfway, the server can still acquire meaningful truth. Rigorous security analysis and extensive experimental results demonstrate the privacy and efficiency of our scheme, respectively.
Chenfei Hu, Yuhua Xu 0010, Chuan Zhang 0003, Ximeng Liu, Daojing He, Liehuang Zhu
IEEE Internet Things J.6
2024 Publicly Verifiable and Secure SVM Classification for Cloud-Based Health Monitoring Services
abstract
In cloud-based health monitoring services, healthcare centers often outsource support vector machine (SVM)-based clinical decision models to provide remote users with clinical decisions. During service provisioning, authorized external organizations like insurance companies aim to verify decision correctness to prevent fraudulent medical reimbursements. However, existing verifiable and secure SVM classification schemes have predominantly focused on user self-verification, thereby introducing potential risks of privacy leakage (such as input data exposure) in publicly verifiable scenarios. To address the aforementioned limitation, we propose a publicly verifiable and secure SVM classification scheme (PVSSVM) for cloud-based health monitoring services in a malicious setting, which can accommodate the verification needs of users or authorized external organizations with respect to potential malicious results returned by cloud servers. Specifically, we utilize homomorphic encryption and secret sharing to protect the model and data confidentiality in the cloud server, respectively. Based on a multiserver verifiable computation framework, PVSSVM achieves public verification of predicted results. Additionally, we further investigate its performance. Experimental evaluations demonstrate that PVSSVM outperforms existing state-of-the-art solutions in terms of computation and communication overhead. Notably, in the verification scenario of large-scale predictions, the proposed scheme achieves a reduction of approximately 83.71% in computation overhead through batch verification, as compared to one-by-one verification.
Dian Lei, Jinwen Liang, Chuan Zhang 0003, Ximeng Liu, Daojing He, Liehuang Zhu, Song Guo 0001
IEEE Internet Things J.5
2024 UCRTD: An Unequally Clustered Routing Protocol Based on Multihop Threshold Distance for Wireless Sensor Networks
abstract
Cluster head (CH) nodes near the base station (BS) die prematurely due to the need to perform more communication tasks, which can lead to disruption of network connectivity and makes it difficult to achieve the goal of load balancing in Wireless Sensor Networks (WSNs), this problem is known as hot spot problem. To solve this problem, non-uniform clustering strategies have been proposed. However, all the current related non-uniform clustering protocols have some drawbacks, such as the lack of a theoretical basis for the value of the multi-hop threshold distance between clusters, the limited attention to the data transmission process, and the insufficient load balancing of the protocols in the face of complex and variable networks. Based on the above problems, we propose an unequally clustered routing protocol based on multi-hop threshold distance (UCRTD) for WSNs. First, this paper analyzes the energy-saving threshold distance for multi-hop communication in conjunction with the energy consumption model of WSNs, and based on the multi-hop energy-saving threshold distance, a strategy for selecting the best energy-saving relay node is proposed. In intra-cluster communication, considering that medium-sized networks form larger clusters, cluster members (CMs) within the cluster that are farther away from the CH take multi-hop communication. For inter-cluster communication, to maximize the network lifetime, the most energy-efficient CH node with the highest residual energy is selected in the routing phase for alternate multi-hop transmission, and this strategy effectively prolongs the network lifetime and also ensures the load balance of the network. Simulation results show that the proposed UCRTD effectively prolongs the network lifetime and maintains good load balancing under multiple network environments when compared with four existing EEUC, EBUC, EADUC, and EAUCA unequal clustering protocols as well as LEACH protocol.
Zhendong Wang 0002, Weibing Zeng, Shuxin Yang, Daojing He, Sammy Chan
IEEE Internet Things J.4
2024 IB-IADR: Enabling Identity-Based Integrity Auditing and Data Recovery With Fault Localization for Multicloud Storage
abstract
With the increasing prevalence of network cloud storage, an escalating number of users are choosing to entrust their data to the cloud. To guarantee remote data integrity and mitigate irreversible loss in case of a single point of failure, numerous multi-cloud public auditing schemes have been proposed. However, most existing studies primarily focus on storage architectures with multiple copies. In practice, users are required to distribute identical data replicas individually across multiple cloud servers (CSs), resulting in significant communication overhead and substantial consumption of storage resources on these servers. Moreover, there is a lack of secure public auditing schemes that effectively address both fault localization and data recovery challenges. To address these issues and enhance storage data reliability, this paper proposes an identity-based integrity auditing and data recovery scheme with fault localization for multi-cloud storage (hereafter referred to as IB-IADR). Specifically, we design a novel identity-based homomorphic signature to facilitate a lightweight auditing challenge-verification process. Our scheme ensures the uniform distribution of encoded data while minimizing data redundancy across multiple CSs. Additionally, IB-IADR provides robust data recovery capabilities and supports fast and accurate fault localization features, including entity position, file position and data block position. We demonstrate that our scheme is provably secure against forgery attacks on response auditing proofs, based on the hardness assumption of the standard CDH problem and DDH problem. We evaluate the proposed scheme’s performance to demonstrate its utility in multi-cloud storage environments.
Jie Zhao 0015, Hejiao Huang, Daojing He, Yuan Zhang 0006, Kim-Kwang Raymond Choo
IEEE Internet Things J.3
2024 VMEMDA: Verifiable Multidimensional Encrypted Medical Data Aggregation Scheme for Cloud-Based Wireless Body Area Networks
abstract
Compared to conventional wireless body area networks (WBANs), the amount of data processed and the analytical capabilities offered by cloud-based WBANs are significantly more extensive. Nevertheless, the paramount consideration in such contexts remains the security and privacy ramifications. Concurrently, the process where medical cloud server (MCS) computes the response aggregation data may be opaque and there is a risk that (partially) invalid aggregation results may be presented to the task requester, either intentionally (e.g., malicious or cost-saving) or unintentionally (e.g., corruption or processing error). Furthermore, with the different roles played by each data requester, relying solely on a single data aggregation type is no longer sufficient to satisfy the diverse data aggregation requests from these requesters. To this end, this paper proposes a novel verifiable multi-dimensional encrypted medical data aggregation scheme (VMEMDA) for cloud-based WBANs, where we integrate an extended super-increasing sequence with a modified Paillier cryptosystem. Doing so allows us to ensure that each dimensional medical data collected by wireless sensor devices and corresponding square values can be encrypted into a single ciphertext with the chronological time series. This enables MCS to select various aggregation types, such as spatial/temporal data aggregation, to aggregate the multi-source encrypted medical data into a single ciphertext. Then the task requester can conduct diverse privacy-preserving statistical analyses, including sum, average, and variance. Moreover, we utilize a homomorphic hash function to guarantee the encrypted data integrity in a highly efficient way, and we design an unpredictable random sequence and integrate it into the provable data possession mechanism to achieve aggregated data correctness guarantee. Performance evaluation demonstrates that VMEMDA exhibits considerably lower computation and communication overhead compared to other existing multi-dimensional data aggregation schemes.
Jie Zhao 0015, Hejiao Huang, Daojing He, Kim-Kwang Raymond Choo, Zoe Lin Jiang
IEEE Internet Things J.4
2024 A comprehensive survey of smart contract security: State of the art and research directions
Guangfu Wu, Daojing He, Sammy Chan
J. Netw. Comput. Appl.5
2024 A hierarchical hybrid intrusion detection model for industrial internet of things
Zhendong Wang 0002, Daojing He, Sammy Chan
Peer Peer Netw. Appl.4
2024 Improving byzantine fault tolerance based on stake evaluation and consistent hashing
Guangfu Wu, Daojing He, Sammy Chan, Xiaoyan Fu
Peer Peer Netw. Appl.3
2024 A Lightweight and Secure Communication Protocol for the IoT Environment
abstract
Ensuring secure communications for the Internet of Things (IoT) systems remains a challenge. Due to exacting resource limitations of computing, memory, and communication in IoT environments, communication schemes based on asymmetric cryptographic systems can be challenging to deploy. An alternative is to deploy symmetric encryption schemes based on pre-shared keys. However, there are also challenges in designing such schemes and examples include how to achieve an optimal trade-off between security and performance levels while meeting resource consumption requirements. Hence, this paper presents a lightweight key synchronization update algorithm, which is then used as a building block in our proposed lightweight secure communication protocol. The security of the protocol is analyzed to show that it can resist common attacks, such as replay attacks, and man-in-the-middle attacks. We then use Tamarin, a widely accepted security protocol verification tool, for formal verification. In addition, we evaluate the randomness and computational performance of the lightweight key synchronization update algorithm and demonstrate that it outperforms other schemes. We also evaluate the performance of the protocol, in terms of computational and communication costs, to demonstrate utility.
Zikang Ding, Daojing He, Qi Qiao, Xuru Li, Sammy Chan, Kim-Kwang Raymond Choo
IEEE Trans. Dependable Secur. Comput.2
2024 You Can Glimpse but You Cannot Identify: Protect IoT Devices From Being Fingerprinted
abstract
With pervasive IoT networking, traffic-analysis-based IoT fingerprinting techniques have been well researched. For example, by integrating blockchain technology and device fingerprinting, authentication of devices connected to a network can be achieved. Though the primary motivations are identifying vulnerabilities and implementing access control, the techniques could be exploited to trace IoT users’ privacy. We propose a traffic morphing scheme to protect IoT devices from being identified by fingerprinting models. The scheme mainly consists of a morphing policy learning algorithm, a rewarding model, and a time-series-based feature estimation algorithm. Backed by the timely rewarding model, a learning agent produces an optimal policy that perturbs the target fingerprinting model while preserving the original traffic function. The estimation algorithm predicts the feature vectors of unfinished flows to enable live traffic morphing. The scheme's advantage is that it requires minimal knowledge of the fingerprinting model and supports live morphing. Experimental results show that over 81% of the IoT devices become unidentifiable, and the scheme degrades the average F1 score of mainstream fingerprinting models from 0.996 to 0.526. For certain devices and target models, the scheme even reaches 100% effectiveness.
Shuaishuai Tan, Shui Yu 0001, Wenyin Liu, Daojing He, Sammy Chan
IEEE Trans. Dependable Secur. Comput.4
2024 Toward Secure and Verifiable Hybrid Federated Learning
abstract
Reducing computation cost and ensuring update integrity, are key challenges in federated learning (FL). In this paper, we present a secure and verifiable hybrid FL system for training, namely SVHFL. SVHFL enables training models on both plaintext and encrypted data simultaneously. Furthermore, we propose a mutual verification scheme for the integrity of updates in FL. It is a general and efficient scheme that can eliminate malformed updates from clients and enforce the integrity checks of the aggregation results from the server. The training and verification schemes of SVHFL have reduced the computation cost from a quadratic cost to a linear cost. The experimental results demonstrate the practicality of SVHFL.
Runmeng Du, Xuru Li, Daojing He, Kim-Kwang Raymond Choo
IEEE Trans. Inf. Forensics Secur.3
2024 Double-Layer Detection of Internal Threat in Enterprise Systems Based on Deep Learning
abstract
In recent years, phishing mail-mediated attacks are proliferating. When victims are enterprise employees, internal security of the enterprise systems will also be threatened. Facing the advanced phishing email attacks and complex insider threat attacks, enterprise systems equipped with traditional machine learning models cannot detect such attacks effectively. Therefore, we propose a double-layer detection framework in this paper. Firstly, from the perspective of individual security, Long Short-Term Memory (LSTM) and extreme gradient boosting tree (XGBoost) are used to build a phishing email detection model. The model generalization ability and precision rate are improved by adding a custom loss function in the training process. Then, from the perspective of group security, Bidirectional LSTM and Attention mechanism are used to build an insider threat detection model. Our model has better results for multi-domain time series and anomaly detection in comparison to different models and existing insider threat detection models. We test the effectiveness of the proposed framework through real phishing email cases and insider threat attack events on our simulation verification platform. The experimental results demonstrate that our proposed framework can protect enterprise systems from phishing attacks and insider threats.
Daojing He, Xueqian Xu, Sammy Chan, Kim-Kwang Raymond Choo
IEEE Trans. Inf. Forensics Secur.1
2023 Blockchain-Assisted Privacy-Preserving Public Auditing Scheme for Cloud Storage Systems
Wenyu Xiang, Jie Zhao 0015, Hejiao Huang, Zoe Lin Jiang, Daojing He
ICA3PP (2)6
2023 Password Cracking by Exploiting User Group Information
Beibei Zhou, Daojing He, Sencun Zhu, Sammy Chan
SecureComm (1)2
2023 Detecting Union Type Confusion in Component Object Model
Xiaogang Zhu 0001, Daojing He, Minhui Xue 0001, Shouling Ji, Mohammad Sayad Haghighi, Sheng Wen, Zhiniang Peng
USENIX Security Symposium3
2023 Residual Vector Product Quantization for approximate nearest neighbor search
Lushuai Niu, Zhi Xu 0005, Longyang Zhao, Daojing He, Jianqiu Ji, Xiaoli Yuan, Mian Xue
Expert Syst. Appl.4
2023 Application of Deep Neural Network with Frequency Domain Filtering in the Field of Intrusion Detection
abstract
In the field of intrusion detection, existing deep learning algorithms have limited capability to effectively represent network data features, making it challenging to model the complex mapping relationship between network data and attack behavior. This limitation, in turn, impacts the detection accuracy of intrusion detection systems. To address this issue and further enhance detection accuracy, this paper proposes an algorithm called the Fourier Neural Network (FNN). The core of FNN consists of a Deep Fourier Neural Network Block (DFNNB), which is composed of a Hadamard Neural Network (HNN) and a Fourier Neural Network Layer (FNNL). In a DFNNB, the HNN is responsible for sampling the network intrusion data samples in different time domain spaces. The FNNL, on the other hand, performs a Fourier transform on the samples outputted by the HNN and maps them to the frequency domain space, followed by a filtering process. Finally, the data processed by filtering are transformed back to the time domain space for subsequent feature extraction work by the DFNNB. Additionally, to enhance the algorithm’s detection accuracy and filter out noise signals, this paper also introduces a High‐energy Filtering Process (HFP), which eliminates noise signals from the data signal and reduces interference on the final detection result. Due to the ability of FNN to process network data in both the time domain space and the frequency domain space, it possesses a stronger capability in expressing data features. Finally, this paper conducts performance evaluations on the KDD Cup99, NSL‐KDD, UNSW‐NB15, and CICIDS2017 datasets. The results demonstrate that the proposed FNN‐based IDS model achieves higher detection rates, lower false alarm rates, and better detection performance than classical deep learning and machine learning methods.
Zhendong Wang 0002, Jingfei Li, Zhenyu Xu 0010, Shuxin Yang, Daojing He, Sammy Chan
Int. J. Intell. Syst.5
2023 Detection of Vulnerabilities of Blockchain Smart Contracts
abstract
With the wide application of Internet of Things and blockchain, research on smart contracts has received increased attention, and security threat detection for smart contracts is one of the main focuses. This article first introduces the common security vulnerabilities in blockchain smart contracts, and then classifies the vulnerabilities detection tools for smart contracts into six categories according to the different detection methods: 1) formal verification method; 2) symbol execution method; 3) fuzzy testing method; 4) intermediate representation method; 5) stain analysis method; and 6) deep learning method. We test 27 detection tools and analyze them from several perspectives, including the capability of detecting a smart contract version. Finally, it is concluded that most of the current vulnerability detection tools can only detect vulnerabilities in a single and old version of smart contracts. Although the deep learning method detects fewer types of smart contract vulnerabilities, it has higher detection accuracy and efficiency. Therefore, the combination of static detection methods, such as deep learning method and dynamic detection methods, including the fuzzy testing method to detect more types of vulnerabilities in multi-version smart contracts to achieve higher accuracy is a direction worthy of research in the future.
Daojing He, Rui Wu 0015, Xinji Li, Sammy Chan, Mohsen Guizani
IEEE Internet Things J.1
2023 A Novel Authentication Protocol for IoT-Enabled Devices
abstract
The Internet of Things (IoT) is composed of a large number of miniaturized devices interconnected through the Internet. These devices, equipped with sensing, computing, and communication capabilities, can be used to remotely control the environment or the monitored infrastructure. However, IoT devices usually only have limited resources, and thus designing a lightweight security authentication protocol for them is a challenge. This article proposes an identity authentication protocol between embedded devices and server. The protocol uses the elliptic curve encryption algorithm and realizes the anonymity of the device by hashing their IDs and prevents the server from replay attacks by adding security attributes timestamp. We prove the security of the protocol and its resistance to security attacks and also formally verify it using the AVISPA tool. In addition, through experimental comparison with existing protocols, we demonstrate the performance superiority of the proposed protocol.
Daojing He, Ziming Zhao 0009, Sammy Chan, Mohsen Guizani
IEEE Internet Things J.1
2023 Hitting Moving Targets: Intelligent Prevention of IoT Intrusions on the Fly
abstract
Massive Internet of Things (IoT) devices have been playing a critical role in both the cyber and physical worlds. Various cyber attacks pose significant risks to IoT. Machine learning-based intrusion detection system (IDS) has earned much research attention. However, the intrusion prevention system (IPS) is rarely explored. Realtime intrusion prevention is quite challenging because the decision has to be made during a flow rather than after it finishes. Restricted by aligning with the shortest flows, existing IPSs generally inspect only the very first packets, leading to information loss for accurate detection. In this article, we first measure the information loss quantitatively. Then we devise Sniper, an IoT IPS scheme consisting of a flow length predictor, a novel feature space, and an enhanced ensemble learning algorithm. The flow length predictor guides a proper prevention time point to preserve as much information as possible. The proposed Markov matrix-based feature encoding method further saves more information than existing ones. The enhanced learning algorithm ensures a low-false positive rate (FPR), which is critical for IPSs. We benchmark Sniper with one closed-world and three open-world data sets. The results show that Sniper achieves a 99.89% prevention rate and 0.03% FPR, which is superior to the five state-of-the-art baseline models.
Shuaishuai Tan, Wenyin Liu, Qingkuan Dong, Sammy Chan, Shui Yu 0001, Xiaoxiong Zhong, Daojing He
IEEE Internet Things J.7
2023 Lightweight certificateless privacy-preserving integrity verification with conditional anonymity for cloud-assisted medical cyber-physical systems
Jie Zhao 0015, Hejiao Huang, Jing Wang 0036, Daojing He
J. Syst. Archit.6
2023 LIGHT: Lightweight Authentication for Intra Embedded Integrated Electronic Systems
abstract
As embedded integrated electronic systems (EIESs) become more pervasive (including in mission-critical applications), the need to ensure the security of data exchange in such a system against various malicious activities becomes more pronounced. However, designing secure and efficient solutions, such as authentication protocols, for the many different embedded systems with varying internal communication modes remains challenging. Therefore, in this paper, we propose a lightweight authenticated key-exchange (AKE) protocol for EIESs based on half-duplex and “command/response” bus. Specifically, the proposed protocol is designed to operate on resource-constrained devices, as well as having minimal number of interactions. We then prove the security of the proposed protocol and present the security parameter selection strategy for protocol implementation based on the empirical evaluations. Moreover, efficiency analysis also shows that the protocol can be effectively deployed in the EIESs environment.
Xuru Li, Daojing He, Ximeng Liu, Sammy Chan, Manghan Pan, Kim-Kwang Raymond Choo
IEEE Trans. Dependable Secur. Comput.2
2023 A Lightweight Authentication and Key Exchange Protocol With Anonymity for IoT
abstract
The number of IoT devices is growing rapidly, and the interaction between devices and servers is also more frequent. However, IoT devices are often at the edge of the network, which leads their communications with the server to be completely exposed, making it more vulnerable to attacks. Moreover, IoT devices have limited energy and computational resources. Therefore, we propose in this paper a lightweight authentication and key exchange protocol with anonymity for IoT devices. The proposed scheme supports mutual authentication between IoT devices and the server. We verify the security of the protocol through formal and informal analyses. Finally, we compare security and performance with other protocols, which shows that our protocol has the advantages of being lightweight and secure.
Daojing He, Yanchang Cai, Ziming Zhao 0009, Sammy Chan, Mohsen Guizani
IEEE Trans. Wirel. Commun.1
2022 A lightweight approach for network intrusion detection in industrial cyber-physical systems based on knowledge distillation and deep metric learning
Zhendong Wang 0002, Daojing He, Sammy Chan
Expert Syst. Appl.3
2022 Design and Formal Analysis of a Lightweight MIPv6 Authentication Scheme
abstract
The emergence of mobile IPv6 (MIPv6) significantly affected how we live and work, while it still faces more security threats than traditional wireless networks. On the other hand, most mobile devices have constrained computing and storage resources. The network environment is complex, and the network topology also changes very frequently. Although various security protocols have been proposed for authentication in MIPv6, there are still some challenges. First, most of the subsisting authentication schemes cannot work in resource-constrained environments. Second, each of these authentication protocols has some defects, which may lead to serious consequences. So it is valuable and crucial to conduct security analysis at the design stage of protocols. Currently, most researchers attempt adopting informal methods, which are not as effective and suitable as formal methods. Some researchers have been conscious of the advantages of using formal methods to verify protocols. However, the approaches are too complex to understand for those who are not familiar with formal methods. In light of these challenges, we propose a lightweight MIPv6 authentication scheme for environments with low resources. We conduct a security analysis and performance comparison of the proposed authentication scheme. In particular, we use the SVO logic to formally analyze its security. We also explain how to use this formal method, which can be regarded as an example to better illustrate the application of formal analysis in MIPv6 authentication schemes.
Daojing He, Xuru Li, Sammy Chan, Mohsen Guizani
IEEE Internet Things J.1
2022 Firmware Vulnerabilities Homology Detection Based on Clonal Selection Algorithm for IoT Devices
abstract
With the wide application of Internet of Things (IoT) devices, security attacks against their firmware often occur, which has attracted more attention from the research community. Firmware is an important part of IoT devices, and attacks against them is one of the main means to destroy them. Therefore, firmware security is considered a core of the overall devices’ security. At present, most of the firmware vulnerabilities have a small number of related samples, so it is difficult to use machine learning methods to generate detectors for some of them. Therefore, based on the collected data of related firmware vulnerabilities, this article proposes a firmware vulnerability homology detection method based on the clonal selection algorithm. We design the numerical and structural characteristics of vulnerability functions, train a detector for each function separately, and improve the recall rate of vulnerability detection. Compared with existing machine learning methods, this method only depends on the affinity between the objective function and the detector, which avoids the requirement of a large number of sample data sets. Finally, relevant experiments are carried out to verify the effectiveness of the method.
Daojing He, Xiaohu You 0001, Tinghui Li 0003, Sammy Chan, Mohsen Guizani
IEEE Internet Things J.1
2022 Traffic Sign Recognition Based on Semantic Scene Understanding and Structural Traffic Sign Location
abstract
Traffic sign recognition (TSR) plays an important role in driving assistance system and traffic safety insurance. However, existing methods focus on extracting features of traffic signs and ignore the constraints of spatial positional relationships between traffic signs and other objects in the scene. This way results in incorrectly detecting other similar objects as traffic signs and failing to detect very small traffic signs. A TSR method based on semantic scene understanding and structural traffic sign location is proposed in this study to solve the aforementioned problems. A scene structure model based on the constraints of spatial positional relationships between traffic signs and other objects is proposed to establish trusted search regions. An improved Light-weight RefineNet is used to analyze and understand a scene semantically and accurately and then segment objects in complicated environments precisely. A new network multiscale densely connected object detector (MDCOD) based on densely connected style, multiscale feature fusion, and improved K-means++ algorithms is proposed to recognize very small traffic signs. The trusted traffic signs are found by filtering false candidates outside the scene structure model. The proposed method is tested on Tsinghua-Tencent 100K and German Traffic Sign Detection Benchmark datasets and achieves accuracies of 92.8% and 99.90%, respectively, outperforming the existing methods.
Weidong Min, Ruikang Liu, Daojing He, Qingting Wei, Qi Wang 0061
IEEE Trans. Intell. Transp. Syst.3
2021 A Lightweight Certificateless Non-interactive Authentication and Key Exchange Protocol for IoT Environments
abstract
In order to protect user privacy and provide better access control in Internet of Things (IoT) environments, designing an appropriate two-party authentication and key exchange protocol is a prominent challenge. In this paper, we propose a lightweight certificateless non-interactive authentication and key exchange (CNAKE) protocol for mutual authentication between remote users and smart devices. Based on elliptic curves, our lightweight protocol provides high security performance, realizes non-interactive authentication between the two entities, and effectively reduces communication overhead. Under the random oracle model, the proposed protocol is provably secure based on the Computational Diffie-Hellman and Bilinear Diffie-Hellman hardness assumption. Finally, through a series of experiments and comprehensive performance analysis, we demonstrate that our scheme is fast and secure.
Menghan Pan, Daojing He, Xuru Li, Sammy Chan, Emmanouil A. Panaousis
ISCC2
2021 Local Model Privacy-Preserving Study for Federated Learning
Kaiyun Pan, Daojing He, Chuan Xu 0002
SecureComm (1)2
2021 Intrusion detection methods based on integrated deep learning model
Zhendong Wang 0002, Yaodi Liu, Daojing He, Sammy Chan
Comput. Secur.3
2021 Feature selection-based android malware adversarial sample generation and detection method
abstract
Abstract With the popularisation of Android smartphones, the value of mobile application security research has increased. The emergence of adversarial technology makes it possible for malware to evade detection. Therefore, research is conducted on Android malicious applications of adversarial attack. To clarify the process and theory of adversarial sample generation, an adversarial sample generation algorithm is proposed that filters features based on feature spatial distribution and definition. These features are modified on real malicious samples to form adversarial samples. In addition, to enhance the robustness of adversarial sample classification detection, a multiple feature set detection algorithm is designed and implemented. Using the frequency differential enhancement feature selection algorithm to perform feature screening, the algorithm forms two different feature sets and establishes two different training sets to train different classification algorithms. Prediction results obtained by the two classification algorithms are integrated based on certain rules. Experimental results on the VirusShare dataset show that both algorithms are effective. The detection results in an actual environment also prove the effectiveness of the multiple feature set detection algorithm.
Ke Kong, Pengtao Qin, Daojing He
IET Inf. Secur.5
2021 Offloading Time Optimization via Markov Decision Process in Mobile-Edge Computing
abstract
Computation offloading from a mobile device to the edge server is an emerging paradigm to reduce completion latency of intensive computations in mobile-edge computing (MEC). In order to satisfy the delay-sensitive computing tasks, offloading time, including task uploading time, task execution time, and results downloading time is adopted as the computational performance metrics for offloading nodes that perform offloaded computing tasks for mobile devices. Therefore, how to minimize the offloading time by selecting an optimal offloading node in MEC is of research importance. This work first investigates a MEC system consisting of mobile devices and heterogeneous edge severs that support various radio access technologies. Then, based on the available bandwidth of heterogeneous edge severs and the location of mobile devices, an optimal offloading node selection strategy is formulated as a Markov decision process (MDP), and solved by employing the value iteration algorithm (VIA). Finally, extensive numerical results demonstrate the effectiveness of the proposed strategy over classic strategies in terms of offloading time.
Guisong Yang, Ling Hou, Daojing He, Sammy Chan, Mohsen Guizani
IEEE Internet Things J.4
2021 A mixed data clustering algorithm with noise-filtered distribution centroid and iterative weight adjustment strategy
Zhibin Zhao 0004, Feng Ding 0007, Daojing He
Inf. Sci.5
2021 Deep logarithmic neural network for Internet intrusion detection
Zhendong Wang 0002, Zhenyu Xu 0010, Daojing He, Sammy Chan
Soft Comput.3
2021 Dynamic Control of Fraud Information Spreading in Mobile Social Networks
abstract
Mobile social networks (MSNs) provide real-time information services to individuals in social communities through mobile devices. However, due to their high openness and autonomy, MSNs have been suffering from rampant rumors, fraudulent activities, and other types of misuses. To mitigate such threats, it is urgent to control the spread of fraud information. The research challenge is: how to design control strategies to efficiently utilize limited resources and meanwhile minimize individuals' losses caused by fraud information? To this end, we model the fraud information control issue as an optimal control problem, in which the control resources consumption for implementing control strategies and the losses of individuals are jointly taken as a constraint called total cost, and the minimum total cost becomes the objective function. Based on the optimal control theory, we devise the optimal dynamic allocation of control strategies. Besides, a dynamics model for fraud information diffusion is established by considering the uncertain mental state of individuals, we investigate the trend of fraud information diffusion and the stability of the dynamics model. Our simulation study shows that the proposed optimal control strategies can effectively inhibit the diffusion of fraud information while incurring the smallest total cost. Compared with other control strategies, the control effect of the proposed optimal control strategies is about 10% higher.
Yaguang Lin, Xiaoming Wang 0001, Fei Hao 0001, Yichuan Jiang, Yulei Wu, Geyong Min, Daojing He, Sencun Zhu, Wei Zhao 0001
IEEE Trans. Syst. Man Cybern. Syst.7
2020 Hybrid Intrusion Detection Mechanisms for Integrated Electronic Systems
abstract
While integrated electronic systems (IESs) are widely used in military and civilian applications, their security issues are barely studied. By analyzing the architecture of the system and the characteristics of bus communication, this paper proposes an intrusion detection method based on the message sequence and behavioral rules of subsystems. According to the bus protocol, messages are divided into periodic and aperiodic messages. For the previous, we adopt sequence analysis and propose an algorithm that extract the sequence intelligently to determine if there are anomalies. For aperiodic messages, we detect the anomalies by modeling the system behaviors as decision trees. Through implementing experiments on our simulation system, we demonstrate that the proposed detection is more accurate than the existing schemes while incurring both lower false negative rate and lower false positive rate.
Qi Qiao, Daojing He, Sencun Zhu, Jiahao Gao, Sammy Chan
SECON2
2020 TLP-IDS: A Two-layer Intrusion Detection System for Integrated Electronic Systems
abstract
With the increasing applications of integrated electronic systems (IESs), especially in security critical application scenarios like satellites and aircraft, new vulnerabilities and attacks have emerged recently. To detect the attacks, we propose TLP-IDS, a real-time intrusion detection system (IDS). TLP-IDS includes two layers of detection modules, one based on time and sequence logic and the other based on historical data. For the modules in the first layer, periodic and aperiodic messages are distinguished based on variations of message intervals, and we learnd from the idea of Markov decision process (MDP) in reinforcement learning (RL) to automatically learn the logical relationship between sequences. In the second layer, an online sequence extreme learning machine (OS-ELM) method is deployed to fit the data and further combined with the Weibull distribution function for prediction and detection. To evaluate our system, we implement several attack scenarios on a test bed, and measure the detection performance. Experimental results show that our system can quickly and effectively detect various attacks.
Daojing He, Sencun Zhu, Sammy Chan
SRDS2
2020 Discriminative fine-grained network for vehicle re-identification using two-stage re-ranking
Qi Wang 0061, Weidong Min, Daojing He, Song Zou, Tiemei Huang, Ruikang Liu
Sci. China Inf. Sci.3
2020 Computation offloading time optimisation via Q-learning in opportunistic edge computing
abstract
The emergence of computation offloading can meet the real‐time requirements of computing tasks with intensive computing demands. In this study, the authors use opportunistic communication to construct a network framework for opportunistic edge computing (OEC) to perform computation offloading. Specifically, OEC forms a computing resource pool near the edge servers in the edge layer by gathering idle computing resources. Firstly, the state of the system is defined by the attributes of the computing task, the execution location of the computing task and the location of the terminal device in OEC. Then the computation offloading time is calculated and learned by selecting different offloading nodes. Finally, an optimal offloading node selection strategy based on the Q‐learning algorithm is obtained. Extensive simulations show that the proposed strategy consumes the minimum computation offloading time compared with benchmark algorithms in aspects of the amount of uploaded data, the total number of CPU cycles of the task and the number of computing tasks.
Guisong Yang, Ling Hou, Daojing He, Sammy Chan
IET Commun.5
2020 Location Privacy-Preserving Distance Computation for Spatial Crowdsourcing
abstract
Data privacy, especially location privacy, is paramountly important for protecting individual's information in smart cities in the big data era. One of the examples is in spatial crowdsourcing (SC). It enables people not only to issue spatiotemporal tasks to ask for help as requesters but also to solve others' tasks as workers on the SC platform. While SC brings convenience to people, it also produces severe location privacy problems, which have been recently paid more attention from both academia and industries. In this article, we address the location privacy problem in SC in a practical and secure way. We propose a location privacy-preserving framework for almost all existed mainstream distance computations in the SC system, namely, Euclidean-L3P, Minkowski-L3P, Manhattan-L3P, and Chebyshev-L3P, among which the first two are constructed based on homomorphic encryption and composite-order multilinear mapping while the latter two on the homomorphic encryption and prefix membership verification approach. Location privacy is resolved because of the above techniques having enabled that all distance computations are evaluated through ciphertexts without disclosing any location information. Security analysis shows that our framework can prevent a strong adversary from obtaining participants' location privacy. Performance analysis evaluates computation and communication overheads between protocols. The results show that Euclidean-L3P is more efficient than Manhattan-L3P and Chebyshev-L3P in terms of computation overheads when the SC applications require a small number of participants, a large plaintext space, and a small number of base stations. Moreover, compared with Manhattan-L3P and Chebyshev-L3P, Euclidean-L3P is a better choice in terms of communication overhead.
Song Han 0006, Jianhong Lin, Guangquan Xu, Siqi Ren, Daojing He, Licheng Wang 0004, Leyun Shi
IEEE Internet Things J.6
2019 metrics and methods of video quality assessment: a brief review
Yuan Xia, Guozhi Li, Daojing He
Multim. Tools Appl.5
2018 Privacy-friendly and efficient secure communication framework for V2G networks
abstract
The vehicle‐to‐grid (V2G) technology enables electric vehicles to deliver electricity into power systems, providing them supplementary capacity. On the other hand, a new set of security threats are brought to smart grid participants by V2G networks. However, security and privacy in V2G networks have so far received little attention, despite a rich literature on the design of conceptual structures or the impact of V2G networks on the current grid. In this study, the authors explore the features of V2G communication networks and identify their security challenges for communication functions. The authors then establish a novel and secure communication framework for V2G networks to achieve a balance among security, privacy preservation, efficiency and accountability without relying on any trusted third party. The feasibility of the framework is demonstrated by experimental results.
Daojing He, Sammy Chan, Mohsen Guizani
IET Commun.1
2017 Toward Detecting Collusive Ranking Manipulation Attackers in Mobile App Markets
abstract
Incentivized by monetary gain, some app developers launch fraudulent campaigns to boost their apps' rankings in the mobile app stores. They pay some service providers for boost services, which then organize large groups of collusive attackers to take fraudulent actions such as posting high app ratings or inflating apps' downloads. If not addressed timely, such attacks will increasingly damage the healthiness of app ecosystems. In this work, we propose a novel approach to identify attackers of collusive promotion groups in an app store. Our approach exploits the unusual ranking change patterns of apps to identify promoted apps, measures their pairwise similarity, forms targeted app clusters (TACs), and finally identifies the collusive group members. Our evaluation based on a dataset of Apple's China App store has demonstrated that our approach is able and scalable to report highly suspicious apps and reviewers. App stores may use our techniques to narrow down the suspicious lists for further investigation.
Daojing He, Sencun Zhu, Jingshun Yang
AsiaCCS2
2017 An FPGA-Based Real-Time Moving Object Tracking Approach
Yangyang Ma, ZhiLei Chai, Mingsong Chen 0001, Daojing He
ICA3PP5
2017 Software-Defined-Networking-Enabled Traffic Anomaly Detection and Mitigation
abstract
Traffic anomaly detection has been a principal direction in the network security field, which aims to identify attacks based on significant deviations from the established normal usage profiles. Recently, a new networking paradigm, software defined networking (SDN), has emerged to facilitate effective network control and management. In this paper, we present the advantages of leveraging SDN to detect traffic anomaly, and review recent progresses in this direction. Despite their effectiveness for traditional traffic, SDN-based traffic anomaly detection methods have to face the challenge of continuously increasing network traffic. To this end, we propose two refined algorithms to be used in an anomaly detection framework which can handle voluminous data, and report some experimental results to demonstrate their performance.
Daojing He, Sammy Chan, Xiejun Ni, Mohsen Guizani
IEEE Internet Things J.1
2017 Online/offline signature based on UOV in wireless sensor networks
Jiahui Chen 0002, Shaohua Tang, Daojing He, Yang Tan 0002
Wirel. Networks3
2016 Network Anomaly Detection Using Unsupervised Feature Selection and Density Peak Clustering
Xiejun Ni, Daojing He, Sammy Chan, Farooq Ahmad
ACNS2
2016 FPGA-Based Parallel Implementation of SURF Algorithm
abstract
SURF (Speeded up robust features) detection is used extensively in object detection, tracking and matching. However, due to its high complexity, it is usually a challenge to perform such detection in real time on a general-purpose processor. This paper proposes a parallel computing algorithm for the fast computation of SURF, which is specially designed for FPGAs. By efficiently exploiting the advantages of the architecture of an FPGA, and by appropriately handling the inherent parallelism of the SURF computation, the proposed algorithm is able to significantly reduce the computation time. Our experimental results show that, for an image with a resolution of 640x480, the processing time for computing using SURF is only 0.047 seconds on an FPGA (XC6SLX150T, 66.7 MHz), which is 13 times faster than when performed on a typical i3-3240 CPU (with a 3.4 GHz main frequency) and 249 times faster than when performed on a traditional ARM system (CortexTM-A8, 1 GHz).
Shuaishuai Ding, ZhiLei Chai, Daojing He, Qiwei Peng 0001
ICPADS4
2015 Security-Enhanced Reprogramming with XORs Coding in Wireless Sensor Networks
Daojing He, Sammy Chan
ICICS2
2015 Analyses of several recently proposed group key management schemes
abstract
ABSTRACT Designing group key management schemes is a troubled field. In this paper, we review three schemes recently proposed, including Kayam's scheme for groups with hierarchy, Piao's group key management (KM) scheme, Purushothama's group KM schemes. We point out the problems in each scheme. Kayam's scheme is not secure to collusion attack. Piao's group KM scheme is not secure. The hard problem it bases is not really hard, and the way their scheme uses a hard problem is improper. Purushothama's scheme has an unnecessary design that costs lots of resources and does not give an advantage to the security level and dynamic efficiency of it. We also briefly analyze the underlying reasons why these problems emerge and give suggestions on designing. Copyright © 2014 John Wiley & Sons, Ltd.
Niu Liu, Shaohua Tang, Daojing He
Secur. Commun. Networks4
2015 Secure and Distributed Data Discovery and Dissemination in Wireless Sensor Networks
abstract
A data discovery and dissemination protocol for wireless sensor networks (WSNs) is responsible for updating configuration parameters of, and distributing management commands to, the sensor nodes. All existing data discovery and dissemination protocols suffer from two drawbacks. First, they are based on the centralized approach; only the base station can distribute data items. Such an approach is not suitable for emergent multi-owner-multi-user WSNs. Second, those protocols were not designed with security in mind and hence adversaries can easily launch attacks to harm the network. This paper proposes the first secure and distributed data discovery and dissemination protocol named DiDrip. It allows the network owners to authorize multiple network users with different privileges to simultaneously and directly disseminate data items to the sensor nodes. Moreover, as demonstrated by our theoretical analysis, it addresses a number of possible security vulnerabilities that we have identified. Extensive security analysis show DiDrip is provably secure. We also implement DiDrip in an experimental network of resource-limited sensor nodes to show its high efficiency in practice.
Daojing He, Sammy Chan, Mohsen Guizani, Haomiao Yang
IEEE Trans. Parallel Distributed Syst.1
2015 Accountable and Privacy-Enhanced Access Control in Wireless Sensor Networks
abstract
In general, owners and users of wireless sensor networks (WSNs) are different entities. A user may want to hide his/her data access privacy from anyone else including the network owner and, at the same time, users who misbehave need to be identified. Such requirements necessitate privacy-preserving and accountable access control. In this paper, we develop a novel protocol, named APAC, to satisfy this need. First, APAC can enforce strict access control so that the sensed data is only accessible by the authorized users. Second, APAC offers sophisticated user privacy protection. Third, misbehaving users or owners can be audited and pinpointed. Last but not least, it does not rely on the existence of a trusted third party, and thus is more feasible in practice. The feasibility of the APAC is demonstrated by experiments on resource-limited mobile devices and sensor platforms.
Daojing He, Sammy Chan, Mohsen Guizani
IEEE Trans. Wirel. Commun.1
2014 A Novel and Lightweight System to Secure Wireless Medical Sensor Networks
abstract
Wireless medical sensor networks (MSNs) are a key enabling technology in e-healthcare that allows the data of a patient's vital body parameters to be collected by the wearable or implantable biosensors. However, the security and privacy protection of the collected data is a major unsolved issue, with challenges coming from the stringent resource constraints of MSN devices, and the high demand for both security/privacy and practicality. In this paper, we propose a lightweight and secure system for MSNs. The system employs hash-chain based key updating mechanism and proxy-protected signature technique to achieve efficient secure transmission and fine-grained data access control. Furthermore, we extend the system to provide backward secrecy and privacy preservation. Our system only requires symmetric-key encryption/decryption and hash operations and is thus suitable for the low-power sensor nodes. This paper also reports the experimental results of the proposed system in a network of resource-limited motes and laptop PCs, which show its efficiency in practice. To the best of our knowledge, this is the first secure data transmission and access control system for MSNs until now.
Daojing He, Sammy Chan, Shaohua Tang
IEEE J. Biomed. Health Informatics1
2014 Lightweight and Confidential Data Discovery and Dissemination for Wireless Body Area Networks
abstract
As a special sensor network, a wireless body area network (WBAN) provides an economical solution to real-time monitoring and reporting of patients' physiological data. After a WBAN is deployed, it is sometimes necessary to disseminate data into the network through wireless links to adjust configuration parameters of body sensors or distribute management commands and queries to sensors. A number of such protocols have been proposed recently, but they all focus on how to ensure reliability and overlook security vulnerabilities. Taking into account the unique features and application requirements of a WBAN, this paper presents the design, implementation, and evaluation of a secure, lightweight, confidential, and denial-of-service-resistant data discovery and dissemination protocol for WBANs to ensure the data items disseminated are not altered or tampered. Based on multiple one-way key hash chains, our protocol provides instantaneous authentication and can tolerate node compromise. Besides the theoretical analysis that demonstrates the security and performance of the proposed protocol, this paper also reports the experimental evaluation of our protocol in a network of resource-limited sensor nodes, which shows its efficiency in practice. In particular, extensive security analysis shows that our protocol is provably secure.
Daojing He, Sammy Chan, Yan Zhang 0002, Haomiao Yang
IEEE J. Biomed. Health Informatics1
2013 Handauth: Efficient Handover Authentication with Conditional Privacy for Wireless Networks
abstract
Existing mechanisms for handover authentication mainly focus on designing a secure authentication module, little attention has been paid to protect users' privacy when they are authenticated by the access points for data access. Further, most existing approaches do not support user revocation. In this paper, we present a secure and efficient authentication protocol named Handauth. Similar to the mechanisms of this field, Handauth provides user authentication and session key establishment. However, compared to other well-known approaches, Handauth not only enjoys both computation and communication efficiency, but also achieves strong user anonymity and untraceablility, forward secure user revocation, conditional privacy-preservation, AAA server anonymity, access service expiration management, access point authentication, easily scheduled revocation, dynamic user revocation and attack resistance. Experimental results show that the proposed approach is feasible for real applications.
Daojing He, Jiajun Bu, Sammy Chan, Chun Chen 0001
IEEE Trans. Computers1
2013 Secure and Lightweight Network Admission and Transmission Protocol for Body Sensor Networks
abstract
A body sensor network (BSN) is a wireless network of biosensors and a local processing unit, which is commonly referred to as the personal wireless hub (PWH). Personal health information (PHI) is collected by biosensors and delivered to the PWH before it is forwarded to the remote healthcare center for further processing. In a BSN, it is critical to only admit eligible biosensors and PWH into the network. Also, securing the transmission from each biosensor to PWH is essential not only for ensuring safety of PHI delivery, but also for preserving the privacy of PHI. In this paper, we present the design, implementation, and evaluation of a secure network admission and transmission subsystem based on a polynomial-based authentication scheme. The procedures in this subsystem to establish keys for each biosensor are communication efficient and energy efficient. Moreover, based on the observation that an adversary eavesdropping in a BSN faces inevitable channel errors, we propose to exploit the adversary's uncertainty regarding the PHI transmission to update the individual key dynamically and improve key secrecy. In addition to the theoretical analysis that demonstrates the security properties of our system, this paper also reports the experimental results of the proposed protocol on resource-limited sensor platforms, which show the efficiency of our system in practice.
Daojing He, Chun Chen 0001, Sammy Chan, Jiajun Bu, Pingxin Zhang
IEEE J. Biomed. Health Informatics1
2013 Grouping-Proofs-Based Authentication Protocol for Distributed RFID Systems
abstract
Along with radio frequency identification (RFID) becoming ubiquitous, security issues have attracted extensive attentions. Most studies focus on the single-reader and single-tag case to provide security protection, which leads to certain limitations for diverse applications. This paper proposes a grouping-proofs-based authentication protocol (GUPA) to address the security issue for multiple readers and tags simultaneous identification in distributed RFID systems. In GUPA, distributed authentication mode with independent subgrouping proofs is adopted to enhance hierarchical protection; an asymmetric denial scheme is applied to grant fault-tolerance capabilities against an illegal reader or tag; and a sequence-based odd-even alternation group subscript is presented to define a function for secret updating. Meanwhile, GUPA is analyzed to be robust enough to resist major attacks such as replay, forgery, tracking, and denial of proof. Furthermore, performance analysis shows that compared with the known grouping-proof or yoking-proof-based protocols, GUPA has lower communication overhead and computation load. It indicates that GUPA realizing both secure and simultaneous identification is efficient for resource-constrained distributed RFID systems.
Hong Liu 0006, Huansheng Ning, Yan Zhang 0002, Daojing He, Qingxu Xiong, Laurence T. Yang
IEEE Trans. Parallel Distributed Syst.4
2013 Secure Data Discovery and Dissemination based on Hash Tree for Wireless Sensor Networks
abstract
Wireless sensor networks (WSNs) are widely applicable in monitoring and control of environment parameters. It is sometimes necessary to disseminate data through wireless links after they are deployed in order to adjust configuration parameters of sensors or distribute management commands and queries to sensors. Several approaches have been proposed recently for data discovery and dissemination in WSNs. However, they all focus on how to ensure reliability and usually overlook security vulnerabilities. This paper identifies the security vulnerabilities in data discovery and dissemination when used in WSNs. Such vulnerabilities allow an adversary to update a network with undesirable values, erase critical variables, or launch denial-of-service (DoS) attacks. To address these vulnerabilities, this paper presents the design, implementation, and evaluation of a secure, lightweight, and DoS-resistant data discovery and dissemination protocol named SeDrip for WSNs. Our protocol takes into consideration the limited resources of sensor nodes, packet loss and out-of-sequence packet delivery. Also, it can provide instantaneous authentication without packet buffering delay, and tolerate node compromise. Besides the theoretical analysis that demonstrates the security and performance of SeDrip, this paper also reports the experimental evaluation of SeDrip in a network of resource-limited sensor nodes, which shows its efficiency in practice.
Daojing He, Sammy Chan, Shaohua Tang, Mohsen Guizani
IEEE Trans. Wirel. Commun.1
2012 Secure and efficient dynamic program update in wireless sensor networks
abstract
ABSTRACT Dynamic program update protocols provide a convenient way to reprogram sensor nodes after deployment. However, designing a secure program update protocol for wireless sensor networks is a difficult task because wireless networks are susceptible to attacks and nodes have limited resources. Recently, two secure program update protocols using orthogonality principle have been found to be vulnerable to two impersonation attacks, although these attacks are rather restrictive. This paper reports one new attack that is more general and makes the program update protocols even more vulnerable. With this attack, an attacker can easily impersonate the base station to install his/her preferred program on sensor nodes and then obtain control over the network. As a remedy, two simple countermeasures are suggested to defend against all these attacks. Finally, the security properties of the two proposed solutions are formally validated by a model checking tool. Copyright © 2011 John Wiley & Sons, Ltd.
Daojing He, Sammy Chan, Chun Chen 0001, Jiajun Bu
Secur. Commun. Networks1
2012 Cryptanalysis of some conference schemes for mobile communications
abstract
ABSTRACT To allow many users to hold a secure teleconference in mobile networks, a secure conference scheme with dynamic participation is necessary. However, designing a secure and efficient conference scheme is a difficult task because wireless networks are susceptible to attacks and wireless devices have limited resources. Recently, a lightweight and secure conference scheme has been suggested. Later, it has been found that this solution has security weaknesses and a modified version to overcome them has been presented. Compared with other conference schemes, these two schemes have many advantages. In this short paper, security study of these conference schemes in mobile networks has been performed with the following findings: (1) both the original scheme and the modified version are still vulnerable to our proposed impersonation attack; (2) they lack a mechanism to confirm the delivery of relevant messages, leading to protocol disruption. Therefore, these two schemes cannot be deployed for the real world applications without further development. Then, some efficient countermeasures are given for enhancing the security of both schemes. Further, the security properties of the improved protocol are formally validated by a model checking tool called AVISPA. Finally, several basic principles are suggested for the design of a secure conference scheme. Copyright © 2011 John Wiley & Sons, Ltd.
Daojing He, Chun Chen 0001, Maode Ma, Jiajun Bu
Secur. Commun. Networks1
2012 ReTrust: Attack-Resistant and Lightweight Trust Management for Medical Sensor Networks
abstract
Wireless medical sensor networks (MSNs) enable ubiquitous health monitoring of users during their everyday lives, at health sites, without restricting their freedom. Establishing trust among distributed network entities has been recognized as a powerful tool to improve the security and performance of distributed networks such as mobile ad hoc networks and sensor networks. However, most existing trust systems are not well suited for MSNs due to the unique operational and security requirements of MSNs. Moreover, similar to most security schemes, trust management methods themselves can be vulnerable to attacks. Unfortunately, this issue is often ignored in existing trust systems. In this paper, we identify the security and performance challenges facing a sensor network for wireless medical monitoring and suggest it should follow a two-tier architecture. Based on such an architecture, we develop an attack-resistant and lightweight trust management scheme named ReTrust. This paper also reports the experimental results of the Collection Tree Protocol using our proposed system in a network of TelosB motes, which show that ReTrust not only can efficiently detect malicious/faulty behaviors, but can also significantly improve the network performance in practice.
Daojing He, Chun Chen 0001, Sammy Chan, Jiajun Bu, Athanasios V. Vasilakos
IEEE Trans. Inf. Technol. Biomed.1
2012 A Distributed Trust Evaluation Model and Its Application Scenarios for Medical Sensor Networks
abstract
The development of medical sensor networks (MSNs) is imperative for e-healthcare, but security remains a formidable challenge yet to be resolved. Traditional cryptographic mechanisms do not suffice given the unique characteristics of MSNs, and the fact that MSNs are susceptible to a variety of node misbehaviors. In such situations, the security and performance of MSNs depend on the cooperative and trust nature of the distributed nodes, and it is important for each node to evaluate the trustworthiness of other nodes. In this paper, we identify the unique features of MSNs and introduce relevant node behaviors, such as transmission rate and leaving time, into trust evaluation to detect malicious nodes. We then propose an applicationindependent and distributed trust evaluation model for MSNs. The trust management is carried out through the use of simple cryptographic techniques. Simulation results demonstrate that the proposed model can be used to effectively identify malicious behaviors and thereby exclude malicious nodes. This paper also reports the experimental results of the Collection Tree Protocol with the addition of our proposed model in a network of TelosB motes, which show that the network performance can be significantly improved in practice. Further, some suggestions are given on how to employ such a trust evaluation model in some application scenarios.
Daojing He, Chun Chen 0001, Sammy Chan, Jiajun Bu, Athanasios V. Vasilakos
IEEE Trans. Inf. Technol. Biomed.1
2012 Secure and Efficient Handover Authentication Based on Bilinear Pairing Functions
abstract
Seamless handover over multiple access points is highly desirable to mobile nodes, but ensuring security and efficiency of this process is challenging. This paper shows that prior handover authentication schemes incur high communication and computation costs, and are subject to a few security attacks. Further, a novel handover authentication protocol named PairHand is proposed. PairHand uses pairing-based cryptography to secure handover process and to achieve high efficiency. Also, an efficient batch signature verification scheme is incorporated into PairHand. Experiments using our implementation on laptop PCs show that PairHand is feasible in real applications.
Daojing He, Chun Chen 0001, Sammy Chan, Jiajun Bu
IEEE Trans. Wirel. Commun.1
2012 DiCode: DoS-Resistant and Distributed Code Dissemination in Wireless Sensor Networks
abstract
Code dissemination in a wireless sensor network (WSN) is the process of propagating a new program image or relevant commands to sensor nodes. As a WSN is usually deployed in hostile environments, secure code dissemination is and will continue to be a major concern. Most code dissemination protocols are based on the centralized approach in which only the base station has the authority to initiate code dissemination. However, it is desirable and sometimes necessary to disseminate code images in a distributed manner which allows multiple authorized network users to simultaneously and directly update code images on different nodes without involving the base station. Motivated by this consideration, we develop a secure and distributed code dissemination protocol named DiCode. A salient feature of DiCode is its ability to resist denial-of-service attacks which have severe consequences on network availability. Further, the security properties of our protocol are demonstrated by theoretical analysis. To verify the efficiency of the proposed approach in practice, we also implement the proposed mechanism in a network of resource-constrained sensor nodes.
Daojing He, Chun Chen 0001, Sammy Chan, Jiajun Bu
IEEE Trans. Wirel. Commun.1
2011 Distributed privacy-preserving access control in a single-owner multi-user sensor network
abstract
A distributed access control module in wireless sensor networks (WSNs) allows the network to authorize and grant user access privileges for in-network data access. Prior research mainly focuses on designing such access control modules for WSNs, but little attention has been paid to protect user's identity privacy when a user is verified by the network for data accesses. Often, a user does not want the WSN to associate his identity to the data he requests, particularly in a single-owner multi-user WSN. In this paper, we present the design, implementation, and evaluation of a novel approach, Priccess, to ensure privacy-preserving access control. In addition to the theoretical analysis that demonstrates the security properties of Priccess, this paper also reports the experimental results of Priccess in a network of Imote2 motes, which show the efficiency of Priccess in practice.
Daojing He, Jiajun Bu, Sencun Zhu, Mingjian Yin, Yi Gao 0001, Sammy Chan, Chun Chen 0001
INFOCOM1
2011 ICAD: Indirect correlation based anomaly detection in dynamic WSNs
abstract
Anomaly detection is an essential functionality of Wireless Sensor Networks (WSNs) due to their complex behaviors and the wireless dynamics. In dynamic WSNs, many characteristics such as network topology, locations of sensor nodes, change frequently over time. We observe that indirect correlations among multiple attributes of a sensor node can be utilized to capture and model the historical behaviors. Prior studies overlooked indirect correlations while in this study we exploit it for detecting anomaly efficiently and accurately. Therefore, we propose ICAD, an indirect correlation based anomaly detection approach. By applying the Markov chain, the state transition probability matrix is calculated and it is subsequently used to detect anomalies. Compared to prior approaches, ICAD can detect different types of anomalies simultaneously. Furthermore, ICAD is implemented based on TinyOS and evaluated in a test-bed with 17 TelosB motes. Evaluation results show that ICAD has high detection accuracy with acceptable overhead.
Yi Gao 0001, Chun Chen 0001, Jiajun Bu, Wei Dong 0001, Daojing He
WCNC5
2011 A strong user authentication scheme with smart cards for wireless communications
Daojing He, Maode Ma, Yan Zhang 0002, Chun Chen 0001, Jiajun Bu
Comput. Commun.1
2011 An efficient and DoS-resistant user authentication scheme for two-tiered wireless sensor networks
abstract
Wireless sensor networks (WSNs) are vulnerable to security attacks due to their deployment and resource constraints. Considering that most large-scale WSNs follow a two-tiered architecture, we propose an efficient and denial-of-service (DoS)-resistant user authentication scheme for two-tiered WSNs. The proposed approach reduces the computational load, since it performs only simple operations, such as exclusive-OR and a one-way hash function. This feature is more suitable for the resource-limited sensor nodes and mobile devices. And it is unnecessary for master nodes to forward login request messages to the base station, or maintain a long user list. In addition, pseudonym identity is introduced to preserve user anonymity. Through clever design, our proposed scheme can prevent smart card breaches. Finally, security and performance analysis demonstrates the effectiveness and robustness of the proposed scheme.
Daojing He, Xuezeng Pan, Lingdi Ping
J. Zhejiang Univ. Sci. C2
2011 Privacy-Preserving Universal Authentication Protocol for Wireless Communications
abstract
Seamless roaming over wireless networks is highly desirable to mobile users, and security such as authentication of mobile users is challenging. In this paper, we propose a privacy-preserving universal authentication protocol, called Priauth, which provides strong user anonymity against both eavesdroppers and foreign servers, session key establishment, and achieves efficiency. Most importantly, Priauth provides an efficient approach to tackle the problem of user revocation while supporting strong user untraceability.
Daojing He, Jiajun Bu, Sammy Chan, Chun Chen 0001, Mingjian Yin
IEEE Trans. Wirel. Commun.1
2011 Distributed Access Control with Privacy Support in Wireless Sensor Networks
abstract
A distributed access control module in wireless sensor networks (WSNs) allows the network to authorize and grant user access privileges for in-network data access. Prior research mainly focuses on designing such access control modules for WSNs, but little attention has been paid to protect user's identity privacy when a user is verified by the network for data accesses. Often, a user does not want the WSN to associate his identity to the data he requests. In this paper, we present the design, implementation, and evaluation of a novel approach, Priccess, to ensure distributed privacy-preserving access control. In Priccess, users who have similar access privileges are organized into the same group by the network owner. A network user signs a query command on behalf of his group and then sends the signed query to the sensor nodes of his interest. The signature can be verified by its recipient as coming from someone authorized without exposing the actual signer. In addition to the theoretical analysis that demonstrates the security properties of Priccess, this paper also reports the experimental results of Priccess in a network of Imote2 motes, which show the efficiency of Priccess in practice.
Daojing He, Jiajun Bu, Sencun Zhu, Sammy Chan, Chun Chen 0001
IEEE Trans. Wirel. Commun.1
2009 Design and Verification of Enhanced Secure Localization Scheme in Wireless Sensor Networks
abstract
In this paper, we focus on the need for secure and efficient localization for wireless sensor networks in adversarial settings. An attack-resistant and efficient localization scheme is developed, which extends the scheme proposed in [1]. The method offers strong defense against not only distance reduction attacks but also distance enlargement attacks. Furthermore, our method does not employ any device-dependent variables, hence yields more accurate localization. An attack-driven model is also specified using Petri net. It provides a formal method for the verification of our scheme when considering distance enlargement attacks. The state analysis shows that the potential insecure states are unreachable, implying that the model can offer strong defense against these attacks. To the best of our knowledge, it is the first time that the Petri net has been introduced to validate security scheme for wireless sensor networks in the literature.
Daojing He, Hejiao Huang, Maode Ma
IEEE Trans. Parallel Distributed Syst.1